Google LLC Vulnerabilities and Affected Products
Vulnerabilities associated with Exposure Notifications Verification Server.
Products
Clear product- Asylo16 vulnerabilities
- Dart SDK4 vulnerabilities
- fscrypt3 vulnerabilities
- guest-oslogin3 vulnerabilities
- AWS S3 Crypto SDK for GoLang2 vulnerabilities
- Fuchsia2 vulnerabilities
- Fuchsia Kernel2 vulnerabilities
- libjxl2 vulnerabilities
- Android Play Core1 vulnerability
- Bazel1 vulnerability
- Bindiff1 vulnerability
- Brotli1 vulnerability
- Dart1 vulnerability
- Data-Transfer-Project1 vulnerability
- Drive for Desktop MacOS1 vulnerability
- Exposure Notifications Verification Server1 vulnerability
- Gerrit1 vulnerability
- go-attestation1 vulnerability
- Google Cloud IoT Device SDK for Embedded C1 vulnerability
- Google Earth Pro1 vulnerability
- Google Exposure-notifications-verification-server1 vulnerability
- Google Play Services SDK1 vulnerability
- Google-oauth-java-client1 vulnerability
- google-protobuf [JRuby Gem]1 vulnerability
- google/go-tpm library1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-22538MEDIUM | Privilege escalation in RBAC systemA privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own. This occurs due to insufficient checks on the allowed set of permissions. The new user creation event would be captured in the Event Log. | CVSS6.3v3.1 | EPSS0.718% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |