Vulnerabilities > Luca APP

DATE CVE VULNERABILITY TITLE RISK
2021-06-04 CVE-2021-33838 Information Exposure Through Discrepancy vulnerability in Luca-App Luca
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because requests related to Check-In State occur shortly after requests for Phone Number Registration.
network
low complexity
luca-app CWE-203
7.5
2021-06-04 CVE-2021-33839 Information Exposure vulnerability in Luca-App Luca
Luca through 1.7.4 on Android allows remote attackers to obtain sensitive information about COVID-19 tracking because the QR code of a Public Location can be intentionally confused with the QR code of a Private Meeting.
network
low complexity
luca-app CWE-200
5.0
2021-06-04 CVE-2021-33840 Insufficient Verification of Data Authenticity vulnerability in Luca-App Luca
The server in Luca through 1.1.14 allows remote attackers to cause a denial of service (insertion of many fake records related to COVID-19) because Phone Number data lacks a digital signature.
network
low complexity
luca-app CWE-345
5.0