CVE-2021-27204

Telegram before 7.4 (212543) Stable on macOS stores the local passcode in cleartext, leading to information disclosure.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:telegram:telegram:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

08 Sep 2021, 17:23

Type Values Removed Values Added
CPE cpe:2.3:o:apple:mac_os:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

14 Feb 2021, 02:11

Type Values Removed Values Added
CWE CWE-312
CVSS v2 : unknown
v3 : unknown
v2 : 2.1
v3 : 5.5
CPE cpe:2.3:o:apple:mac_os:-:*:*:*:*:*:*:*
cpe:2.3:a:telegram:telegram:*:*:*:*:*:*:*:*
References (MISC) https://www.youtube.com/watch?v=zEt-_5b4OaA - (MISC) https://www.youtube.com/watch?v=zEt-_5b4OaA - Exploit, Third Party Advisory
References (MISC) https://www.inputzero.io/2020/12/telegram-privacy-fails-again.html - (MISC) https://www.inputzero.io/2020/12/telegram-privacy-fails-again.html - Third Party Advisory

12 Feb 2021, 08:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-02-12 08:15

Updated : 2023-12-10 13:41


NVD link : CVE-2021-27204

Mitre link : CVE-2021-27204

CVE.ORG link : CVE-2021-27204


JSON object : View

Products Affected

apple

  • macos

telegram

  • telegram
CWE
CWE-312

Cleartext Storage of Sensitive Information