GHSA-wx8q-rgfr-cf6v

    Dashboard / Vulnerabilities / GHSA-wx8q-rgfr-cf6v

    GHSA-wx8q-rgfr-cf6v

    Published: 10 Nov 2021Last Modified: 8 Jul 2026

    Summary: Insufficient Granularity of Access Control in github.com/google/exposure-notifications-verification-server

    Details: ### Impact Users or API keys with permission to expire verification codes could have expired codes that belonged to another realm if they guessed the UUID. ### Patches v1.1.2+ ### Workarounds There are no workarounds, and there are no indications this has been exploited in the wild. Verification codes can only be expired by providing their 64-bit UUID, and verification codes are already valid for a very short period of time (thus the UUID rotates frequently). ### For more information Contact [email protected]

    Affected packages

    Package

    Name: github.com/google/exposure-notifications-verification-server

    Purl: pkg:golang/github.com/google/exposure-notifications-verification-server

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.1.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-wx8q-rgfr-cf6v | CVE-DB