CVE-2021-21400 describes a vulnerability in wire-webapp, an open-source front end for the Wire secure collaboration platform, affecting versions prior to 2021-03-15-production.0. This flaw allows a user's app-lock passphrase to be inadvertently sent to the most recently used chat if the input field is not actively focused when typing. Rated as MEDIUM severity with a CVSS score of 6.5, the vulnerability has a network attack vector and low attack complexity, potentially leading to high confidentiality impact by exposing sensitive passphrases. There is currently no evidence of active exploitation, no public exploit code available (Metasploit, Nuclei, ExploitDB), and minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2019-07-11-13-18CPE matchmatch criteria | cpe:2.3:a:wire:wire-webapp:*:*:*:*:*:*:*:* | ||
2019-02-11CPE matchmatch criteria | cpe:2.3:a:wire:wire-webapp:2019-02-11:staging0:*:*:*:*:*:* | ||
2019-02-11CPE matchmatch criteria | cpe:2.3:a:wire:wire-webapp:2019-02-11:staging1:*:*:*:*:*:* | ||
2019-02-11CPE matchmatch criteria | cpe:2.3:a:wire:wire-webapp:2019-02-11:staging2:*:*:*:*:*:* | ||
2019-02-13CPE matchmatch criteria | cpe:2.3:a:wire:wire-webapp:2019-02-13:staging0:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.