github.com/google/exposure-notifications-verification-server
Go2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/google/exposure-notifications-verification-serverpage 1 of 1
- CVE-2021-22538MEDIUMCVSS 6.3EG 6.3✓ Fixed in 0.23.12021-03-31
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious …
- CVE-2021-22565MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.1.22021-12-09
An attacker could prematurely expire a verification code, making it unusable by the patient, making the patient unable to upload their TEKs to generate exposure notifications. We recommend upgrading the Exposure Notification server to V1.1…
Check whether github.com/google/exposure-notifications-verification-server is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/google/exposure-notifications-verification-server CVEs against the assets you own.
Start Free Scan →