PT-2021-23082 · Wire · Wire

Published

2021-10-04

·

Updated

2022-08-12

·

CVE-2021-41093

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wire versions prior to 3.86
Description The issue allows an attacker to take over an account by changing the email if they obtain an old but valid access token. This is possible due to insufficient security measures in place prior to the resolution in version 3.86. The new version introduces a new endpoint that requires an authentication cookie, enhancing security.
Recommendations For versions prior to 3.86, update to version 3.86 or later to resolve the issue. As a temporary workaround, consider restricting access to account settings until the update is applied.

Fix

Incorrect Authorization

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-41093
GHSA-6F4C-PHFJ-M255
GHSA-9RM2-W6PQ-333M
GHSA-P354-6R3M-G4XR
GHSA-W727-5F74-49XJ

Affected Products

Wire