CVE-2021-32755: Certificate pinning is not enforced on the web socket connection
Wire is a collaboration platform. wire-ios-transport handles authentication of requests, network failures, and retries for the iOS implementation of Wire. In the 3.82 version of the iOS application, a new web socket implementation was introduced for users running iOS 13 or higher. This new websocket implementation is not configured to enforce certificate pinning when available. Certificate pinning for the new websocket is enforced in version 3.84 or above.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32755?
CVE-2021-32755 is a vulnerability that affects the wire-ios-transport component used by the Wire collaboration platform.
What is the severity of CVE-2021-32755?
The severity of CVE-2021-32755 is medium with a CVSS score of 4.3.
How does CVE-2021-32755 affect Wire?
CVE-2021-32755 affects the wire-ios-transport component of the Wire iOS application, specifically in its websocket implementation.
What is the affected software version of CVE-2021-32755?
The affected software version of CVE-2021-32755 is up to but excluding version 3.84 of the Wire iOS application.
Is Apple iPhone OS vulnerable to CVE-2021-32755?
No, Apple iPhone OS is not vulnerable to CVE-2021-32755. The vulnerability only affects the Wire iOS application.
Is there a fix available for CVE-2021-32755?
Yes, a fix for CVE-2021-32755 is available in version 3.84 or later of the Wire iOS application.
Where can I find more information about CVE-2021-32755?
You can find more information about CVE-2021-32755 in the security advisory on the Wire iOS Transport GitHub repository: [link](https://github.com/wireapp/wire-ios-transport/security/advisories/GHSA-v8mx-h3vj-w39v).