RSS   Vulnerabilities for
'Exposure notifications verification server'
   RSS

2021-03-31
 
CVE-2021-22538

CWE-276
 

 
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own. This occurs due to insufficient checks on the allowed set of permissions. The new user creation event would be captured in the Event Log.

 

 >>> Vendor: Google 87 Products
Toolbar
TALK
Mini search appliance
Search appliance
Api search
Earth
Desktop
Web toolkit
Custom search engine
Picasa
KML
Android sdk
Google apps
Chrome
Gears
Android
V8
Google sketchup
Chrome os
App engine python sdk
Idapython
Cr-48 chromebook
Chr2000ome
Sketchup
Chrome2000
Chrom2000e
Bionic
Tunnelblick
Admob
Checkout-php
Cityhash
Android sdk tools
Chrome frame
Frame
Google authenticator
Authenticator
Glass
Android api
Search appliance software
Android debug bridge
Android sdk platform tools
Android browser
Nexus 7
Calendar events
Email
Play services sdk
Kubernetes
Android one
Sfntly
GRPC
Google i/o 2017
News and weather
Protobuf
Gmail
Boringssl
Santa
Chromecast firmware
Home firmware
Mod pagespeed
Rendertron
Cardboard
Kubernetes engine
Guava
Tensorflow
Snappy
Nexus 7 firmware
Nexus 9 firmware
Voice builder
Cloud messaging notification
Nest cam iq indoor firmware
Fscrypt
Blink
Gizmo5
Closure library
Openthread
Chrome-launcher
Asylo
Go-tpm
Brotli
Gerrit
Flatbuffers
Secret manager provider for secret store csi driver
Slashify
Exposure notifications verification server
Bazel
Cloud iot device sdk for embedded c
Bindiff


Copyright 2021, cxsecurity.com

 

Back to Top