Vulnerabilities > CVE-2021-33838 - Information Exposure Through Discrepancy vulnerability in Luca-App Luca

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
network
low complexity
luca-app
CWE-203

Summary

Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration.

Vulnerable Configurations

Part Description Count
Application
Luca-App
1

Common Weakness Enumeration (CWE)