CVE-2021-21301

Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in version 3.75.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wire:wire:*:*:*:*:*:iphone_os:*:*

History

20 Apr 2021, 20:51

Type Values Removed Values Added
CPE cpe:2.3:a:wire:wire:*:*:*:*:*:ipados:*:*

17 Feb 2021, 20:00

Type Values Removed Values Added
References (CONFIRM) https://github.com/wireapp/wire-ios/security/advisories/GHSA-7fg4-x8vj-qvxf - (CONFIRM) https://github.com/wireapp/wire-ios/security/advisories/GHSA-7fg4-x8vj-qvxf - Patch, Third Party Advisory
References (MISC) https://github.com/wireapp/wire-ios/pull/4879 - (MISC) https://github.com/wireapp/wire-ios/pull/4879 - Patch, Third Party Advisory
References (MISC) https://github.com/wireapp/wire-ios/commit/7e3c30120066c9b10e50cc0d20012d0849c33a40 - (MISC) https://github.com/wireapp/wire-ios/commit/7e3c30120066c9b10e50cc0d20012d0849c33a40 - Patch, Third Party Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 4.3
CPE cpe:2.3:a:wire:wire:*:*:*:*:*:iphone_os:*:*
cpe:2.3:a:wire:wire:*:*:*:*:*:ipados:*:*

11 Feb 2021, 19:47

Type Values Removed Values Added
Summary Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in version 3.75. Wire is an open-source collaboration platform. In Wire for iOS (iPhone and iPad) before version 3.75 there is a vulnerability where the video capture isn't stopped in a scenario where a user first has their camera enabled and then disables it. It's a privacy issue because video is streamed to the call when the user believes it is disabled. It impacts all users in video calls. This is fixed in version 3.75.

11 Feb 2021, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-11 18:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-21301

Mitre link : CVE-2021-21301

CVE.ORG link : CVE-2021-21301


JSON object : View

Products Affected

wire

  • wire
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor