CVE-2021-32755 Information

Description

Wire is a collaboration platform. wire-ios-transport handles authentication of requests network failures and retries for the iOS implementation of Wire. In the 3.82 version of the iOS application a new web socket implementation was introduced for users running iOS 13 or higher. This new websocket implementation is not configured to enforce certificate pinning when available. Certificate pinning for the new websocket is enforced in version 3.84 or above.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Reference

https://github.com/wireapp/wire-ios-transport/security/advisories/GHSA-v8mx-h3vj-w39v

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

4.3

Share on: