Medium severity6.3NVD Advisory· Published Mar 31, 2021· Updated Jun 17, 2026
CVE-2021-22538
CVE-2021-22538
Description
A privilege escalation vulnerability impacting the Google Exposure Notification Verification Server (versions prior to 0.23.1), allows an attacker who (1) has UserWrite permissions and (2) is using a carefully crafted request or malicious proxy, to create another user with higher privileges than their own. This occurs due to insufficient checks on the allowed set of permissions. The new user creation event would be captured in the Event Log.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/google/exposure-notifications-verification-serverGo | < 0.23.1 | 0.23.1 |
Affected products
3- cpe:2.3:a:google:exposure_notifications_verification_server:*:*:*:*:*:*:*:*Range: <0.23.1
- Google LLC/Exposure Notifications Verification Serverv5Range: stable
Patches
Vulnerability mechanics
References
6- github.com/google/exposure-notifications-verification-server/commit/eb8cf40b12dbe79304f1133c06fb73419383cd95nvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-5v95-v8c8-3rh6ghsaADVISORY
- github.com/google/exposure-notifications-verification-server/releases/tag/v0.23.1nvdRelease NotesThird Party AdvisoryWEB
- github.com/google/exposure-notifications-verification-server/releases/tag/v0.24.0nvdRelease NotesThird Party AdvisoryWEB
- github.com/google/exposure-notifications-verification-server/security/advisories/GHSA-5v95-v8c8-3rh6nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-22538ghsaADVISORY
News mentions
0No linked articles in our index yet.