PT-2021-23082 · Wire · Wire
Published
2021-10-04
·
Updated
2022-08-12
·
CVE-2021-41093
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wire versions prior to 3.86
Description
The issue allows an attacker to take over an account by changing the email if they obtain an old but valid access token. This is possible due to insufficient security measures in place prior to the resolution in version 3.86. The new version introduces a new endpoint that requires an authentication cookie, enhancing security.
Recommendations
For versions prior to 3.86, update to version 3.86 or later to resolve the issue. As a temporary workaround, consider restricting access to account settings until the update is applied.
Fix
Incorrect Authorization
Improper Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Wire