CVE Vulnerabilities

CVE-2022-23605

Improper Removal of Sensitive Information Before Storage or Transfer

Published: Feb 04, 2022 | Modified: Nov 21, 2024
CVSS 3.x
2.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Wire webapp is a web client for the wire messaging protocol. In versions prior to 2022-01-27-production.0 expired ephemeral messages were not reliably removed from local chat history of Wire Webapp. In versions before 2022-01-27-production.0 ephemeral messages and assets might still be accessible through the local search functionality. Any attempt to view one of these message in the chat view will then trigger the deletion. This issue only affects locally stored messages. On premise instances of wire-webapp need to be updated to 2022-01-27-production.0, so that their users are no longer affected. There are no known workarounds for this issue.

Weakness

The product stores, transfers, or shares a resource that contains sensitive information, but it does not properly remove that information before the product makes the resource available to unauthorized actors.

Affected Software

NameVendorStart VersionEnd Version
Wire-webappWire2016-07-29-17-00 (including)2016-07-29-17-00 (including)
Wire-webappWire2016-08-04-15-44 (including)2016-08-04-15-44 (including)
Wire-webappWire2016-08-23-09-31 (including)2016-08-23-09-31 (including)
Wire-webappWire2016-08-24-10-10 (including)2016-08-24-10-10 (including)
Wire-webappWire2016-08-29-14-54 (including)2016-08-29-14-54 (including)
Wire-webappWire2016-09-08-15-38 (including)2016-09-08-15-38 (including)
Wire-webappWire2016-09-19-14-01 (including)2016-09-19-14-01 (including)
Wire-webappWire2016-09-28-14-58 (including)2016-09-28-14-58 (including)
Wire-webappWire2016-10-11-15-34 (including)2016-10-11-15-34 (including)
Wire-webappWire2016-10-18-08-10 (including)2016-10-18-08-10 (including)
Wire-webappWire2016-10-25-08-17 (including)2016-10-25-08-17 (including)
Wire-webappWire2016-10-26-18-58 (including)2016-10-26-18-58 (including)
Wire-webappWire2016-11-03-16-09 (including)2016-11-03-16-09 (including)
Wire-webappWire2016-11-08-15-06 (including)2016-11-08-15-06 (including)
Wire-webappWire2016-12-01-12-57 (including)2016-12-01-12-57 (including)
Wire-webappWire2016-12-13-15-12 (including)2016-12-13-15-12 (including)
Wire-webappWire2017-01-23-12-12 (including)2017-01-23-12-12 (including)
Wire-webappWire2017-02-01-14-49 (including)2017-02-01-14-49 (including)
Wire-webappWire2017-02-17-10-10 (including)2017-02-17-10-10 (including)
Wire-webappWire2017-02-24-13-06 (including)2017-02-24-13-06 (including)
Wire-webappWire2017-03-08-17-32 (including)2017-03-08-17-32 (including)
Wire-webappWire2017-03-14-15-05 (including)2017-03-14-15-05 (including)
Wire-webappWire2017-03-21-11-00 (including)2017-03-21-11-00 (including)
Wire-webappWire2017-03-27-17-10 (including)2017-03-27-17-10 (including)
Wire-webappWire2017-03-28-14-23 (including)2017-03-28-14-23 (including)
Wire-webappWire2017-04-05-16-58 (including)2017-04-05-16-58 (including)
Wire-webappWire2017-04-07-09-42 (including)2017-04-07-09-42 (including)
Wire-webappWire2017-04-19-12-31 (including)2017-04-19-12-31 (including)
Wire-webappWire2017-04-20-15-54 (including)2017-04-20-15-54 (including)
Wire-webappWire2017-05-03-10-29 (including)2017-05-03-10-29 (including)
Wire-webappWire2017-05-19-16-10 (including)2017-05-19-16-10 (including)
Wire-webappWire2017-05-26-08-16 (including)2017-05-26-08-16 (including)
Wire-webappWire2017-05-26-12-03 (including)2017-05-26-12-03 (including)
Wire-webappWire2017-06-01-10-02 (including)2017-06-01-10-02 (including)
Wire-webappWire2017-06-07-15-03 (including)2017-06-07-15-03 (including)
Wire-webappWire2017-06-07-18-05 (including)2017-06-07-18-05 (including)
Wire-webappWire2017-06-22-12-18 (including)2017-06-22-12-18 (including)
Wire-webappWire2017-06-28-15-13 (including)2017-06-28-15-13 (including)
Wire-webappWire2017-07-06-12-44 (including)2017-07-06-12-44 (including)
Wire-webappWire2017-07-06-15-48 (including)2017-07-06-15-48 (including)
Wire-webappWire2017-07-18-12-50 (including)2017-07-18-12-50 (including)
Wire-webappWire2017-08-03-15-19 (including)2017-08-03-15-19 (including)
Wire-webappWire2017-08-04-09-04 (including)2017-08-04-09-04 (including)
Wire-webappWire2017-08-04-15-01 (including)2017-08-04-15-01 (including)
Wire-webappWire2017-08-08-15-09 (including)2017-08-08-15-09 (including)
Wire-webappWire2017-08-24-10-57 (including)2017-08-24-10-57 (including)
Wire-webappWire2017-08-31-14-21 (including)2017-08-31-14-21 (including)
Wire-webappWire2017-09-26-07-18 (including)2017-09-26-07-18 (including)
Wire-webappWire2017-09-26-13-00 (including)2017-09-26-13-00 (including)
Wire-webappWire2017-10-09-08-42 (including)2017-10-09-08-42 (including)
Wire-webappWire2017-10-19-10-45 (including)2017-10-19-10-45 (including)
Wire-webappWire2017-10-25-07-08 (including)2017-10-25-07-08 (including)
Wire-webappWire2017-11-07-08-50 (including)2017-11-07-08-50 (including)
Wire-webappWire2017-11-10-10-41 (including)2017-11-10-10-41 (including)
Wire-webappWire2017-12-04-10-23 (including)2017-12-04-10-23 (including)
Wire-webappWire2017-12-04-13-34 (including)2017-12-04-13-34 (including)
Wire-webappWire2017-12-07-11-13 (including)2017-12-07-11-13 (including)
Wire-webappWire2017-12-20-12-48 (including)2017-12-20-12-48 (including)
Wire-webappWire2018-01-24-18-11 (including)2018-01-24-18-11 (including)
Wire-webappWire2018-02-01-10-26 (including)2018-02-01-10-26 (including)
Wire-webappWire2018-02-16-07-54 (including)2018-02-16-07-54 (including)
Wire-webappWire2018-03-12-11-41 (including)2018-03-12-11-41 (including)
Wire-webappWire2018-04-06-07-28 (including)2018-04-06-07-28 (including)
Wire-webappWire2018-04-06-09-44 (including)2018-04-06-09-44 (including)
Wire-webappWire2018-04-09-10-16 (including)2018-04-09-10-16 (including)
Wire-webappWire2018-04-12-06-45 (including)2018-04-12-06-45 (including)
Wire-webappWire2018-04-12-11-12 (including)2018-04-12-11-12 (including)
Wire-webappWire2018-04-12-13-37 (including)2018-04-12-13-37 (including)
Wire-webappWire2018-04-24-14-58 (including)2018-04-24-14-58 (including)
Wire-webappWire2018-05-04-07-18 (including)2018-05-04-07-18 (including)
Wire-webappWire2018-05-24-15-49 (including)2018-05-24-15-49 (including)
Wire-webappWire2018-06-19-08-04 (including)2018-06-19-08-04 (including)
Wire-webappWire2018-07-03-08-25 (including)2018-07-03-08-25 (including)
Wire-webappWire2018-07-16-08-55 (including)2018-07-16-08-55 (including)
Wire-webappWire2018-07-16-14-05 (including)2018-07-16-14-05 (including)
Wire-webappWire2018-07-26-08-54 (including)2018-07-26-08-54 (including)
Wire-webappWire2018-08-06-08-03 (including)2018-08-06-08-03 (including)
Wire-webappWire2018-08-22-07-38 (including)2018-08-22-07-38 (including)
Wire-webappWire2018-08-31-06-54 (including)2018-08-31-06-54 (including)
Wire-webappWire2018-09-07-14-18 (including)2018-09-07-14-18 (including)
Wire-webappWire2018-09-28-11-46 (including)2018-09-28-11-46 (including)
Wire-webappWire2018-10-02-08-03 (including)2018-10-02-08-03 (including)
Wire-webappWire2018-10-15-08-14 (including)2018-10-15-08-14 (including)
Wire-webappWire2018-10-23-12-05 (including)2018-10-23-12-05 (including)
Wire-webappWire2018-11-05-11-21 (including)2018-11-05-11-21 (including)
Wire-webappWire2018-11-15-13-14 (including)2018-11-15-13-14 (including)
Wire-webappWire2018-11-30-11-03 (including)2018-11-30-11-03 (including)
Wire-webappWire2018-12-03-11-26 (including)2018-12-03-11-26 (including)
Wire-webappWire2018-12-04-14-24 (including)2018-12-04-14-24 (including)
Wire-webappWire2019-01-02-13-10 (including)2019-01-02-13-10 (including)
Wire-webappWire2019-01-08-13-20 (including)2019-01-08-13-20 (including)
Wire-webappWire2019-01-17-15-08 (including)2019-01-17-15-08 (including)
Wire-webappWire2019-02-11-staging0 (including)2019-02-11-staging0 (including)
Wire-webappWire2019-02-11-staging1 (including)2019-02-11-staging1 (including)
Wire-webappWire2019-02-11-staging2 (including)2019-02-11-staging2 (including)
Wire-webappWire2019-02-13-staging0 (including)2019-02-13-staging0 (including)
Wire-webappWire2019-02-18-staging0 (including)2019-02-18-staging0 (including)
Wire-webappWire2019-02-18-11-26 (including)2019-02-18-11-26 (including)
Wire-webappWire2019-02-27-staging0 (including)2019-02-27-staging0 (including)
Wire-webappWire2019-02-28-staging0 (including)2019-02-28-staging0 (including)
Wire-webappWire2019-02-28-staging1 (including)2019-02-28-staging1 (including)
Wire-webappWire2019-02-28-15-10 (including)2019-02-28-15-10 (including)
Wire-webappWire2019-02-28-15-11 (including)2019-02-28-15-11 (including)
Wire-webappWire2019-03-05-staging0 (including)2019-03-05-staging0 (including)
Wire-webappWire2019-03-07-staging0 (including)2019-03-07-staging0 (including)
Wire-webappWire2019-03-11-staging0 (including)2019-03-11-staging0 (including)
Wire-webappWire2019-03-13-staging0 (including)2019-03-13-staging0 (including)
Wire-webappWire2019-03-13-staging1 (including)2019-03-13-staging1 (including)
Wire-webappWire2019-03-14-11-05 (including)2019-03-14-11-05 (including)
Wire-webappWire2019-03-18-12-58 (including)2019-03-18-12-58 (including)
Wire-webappWire2019-03-20-staging0 (including)2019-03-20-staging0 (including)
Wire-webappWire2019-03-25-staging0 (including)2019-03-25-staging0 (including)
Wire-webappWire2019-03-25-staging1 (including)2019-03-25-staging1 (including)
Wire-webappWire2019-03-28-staging0 (including)2019-03-28-staging0 (including)
Wire-webappWire2019-03-28-staging1 (including)2019-03-28-staging1 (including)
Wire-webappWire2019-03-29-09-38 (including)2019-03-29-09-38 (including)
Wire-webappWire2019-04-08-staging0 (including)2019-04-08-staging0 (including)
Wire-webappWire2019-04-10-10-55 (including)2019-04-10-10-55 (including)
Wire-webappWire2019-04-11-staging0 (including)2019-04-11-staging0 (including)
Wire-webappWire2019-04-18-staging0 (including)2019-04-18-staging0 (including)
Wire-webappWire2019-04-23-staging1 (including)2019-04-23-staging1 (including)
Wire-webappWire2019-04-23-10-51 (including)2019-04-23-10-51 (including)
Wire-webappWire2019-04-25-staging0 (including)2019-04-25-staging0 (including)
Wire-webappWire2019-04-29-staging0 (including)2019-04-29-staging0 (including)
Wire-webappWire2019-05-09-09-36 (including)2019-05-09-09-36 (including)
Wire-webappWire2019-05-14-staging0 (including)2019-05-14-staging0 (including)
Wire-webappWire2019-05-15-staging0 (including)2019-05-15-staging0 (including)
Wire-webappWire2019-05-16 (including)2019-05-16 (including)
Wire-webappWire2019-05-16-09-26 (including)2019-05-16-09-26 (including)
Wire-webappWire2019-05-31-staging0 (including)2019-05-31-staging0 (including)
Wire-webappWire2019-05-31-08-18 (including)2019-05-31-08-18 (including)
Wire-webappWire2019-06-04-staging0 (including)2019-06-04-staging0 (including)
Wire-webappWire2019-06-06-12-31 (including)2019-06-06-12-31 (including)
Wire-webappWire2019-06-20-staging0 (including)2019-06-20-staging0 (including)
Wire-webappWire2019-06-24-staging0 (including)2019-06-24-staging0 (including)
Wire-webappWire2019-06-25-staging0 (including)2019-06-25-staging0 (including)
Wire-webappWire2019-06-26-staging0 (including)2019-06-26-staging0 (including)
Wire-webappWire2019-07-01-staging0 (including)2019-07-01-staging0 (including)
Wire-webappWire2019-07-02-12-29 (including)2019-07-02-12-29 (including)
Wire-webappWire2019-07-11-13-18 (including)2019-07-11-13-18 (including)
Wire-webappWire2019-07-30-staging0 (including)2019-07-30-staging0 (including)
Wire-webappWire2019-08-01-staging0 (including)2019-08-01-staging0 (including)
Wire-webappWire2019-08-14-staging0 (including)2019-08-14-staging0 (including)
Wire-webappWire2019-08-19-staging0 (including)2019-08-19-staging0 (including)
Wire-webappWire2019-08-21-production0 (including)2019-08-21-production0 (including)
Wire-webappWire2019-08-22-production0 (including)2019-08-22-production0 (including)
Wire-webappWire2019-08-22-staging0 (including)2019-08-22-staging0 (including)
Wire-webappWire2019-08-27-staging0 (including)2019-08-27-staging0 (including)
Wire-webappWire2019-09-02-production0 (including)2019-09-02-production0 (including)
Wire-webappWire2019-09-05-staging0 (including)2019-09-05-staging0 (including)
Wire-webappWire2019-09-09-staging0 (including)2019-09-09-staging0 (including)
Wire-webappWire2019-09-12-staging0 (including)2019-09-12-staging0 (including)
Wire-webappWire2019-09-13-staging0 (including)2019-09-13-staging0 (including)
Wire-webappWire2019-09-17-production0 (including)2019-09-17-production0 (including)
Wire-webappWire2019-09-18-staging0 (including)2019-09-18-staging0 (including)
Wire-webappWire2019-09-23-staging0 (including)2019-09-23-staging0 (including)
Wire-webappWire2019-09-24-production0 (including)2019-09-24-production0 (including)
Wire-webappWire2019-10-07-staging0 (including)2019-10-07-staging0 (including)
Wire-webappWire2019-10-07-staging1 (including)2019-10-07-staging1 (including)
Wire-webappWire2019-10-08-staging0 (including)2019-10-08-staging0 (including)
Wire-webappWire2019-10-10-staging0 (including)2019-10-10-staging0 (including)
Wire-webappWire2019-10-10-staging1 (including)2019-10-10-staging1 (including)
Wire-webappWire2019-10-14-staging0 (including)2019-10-14-staging0 (including)
Wire-webappWire2019-10-16-production0 (including)2019-10-16-production0 (including)
Wire-webappWire2019-10-16-production1 (including)2019-10-16-production1 (including)
Wire-webappWire2019-10-16-staging0 (including)2019-10-16-staging0 (including)
Wire-webappWire2019-10-16-staging1 (including)2019-10-16-staging1 (including)
Wire-webappWire2019-10-21-staging0 (including)2019-10-21-staging0 (including)
Wire-webappWire2019-10-25-staging0 (including)2019-10-25-staging0 (including)
Wire-webappWire2019-10-29-staging0 (including)2019-10-29-staging0 (including)
Wire-webappWire2019-10-31-staging0 (including)2019-10-31-staging0 (including)
Wire-webappWire2019-11-01-production0 (including)2019-11-01-production0 (including)
Wire-webappWire2019-11-08-staging0 (including)2019-11-08-staging0 (including)
Wire-webappWire2019-11-12-staging0 (including)2019-11-12-staging0 (including)
Wire-webappWire2019-11-19-staging0 (including)2019-11-19-staging0 (including)
Wire-webappWire2019-11-21-production0 (including)2019-11-21-production0 (including)
Wire-webappWire2019-11-21-staging0 (including)2019-11-21-staging0 (including)
Wire-webappWire2019-11-25-staging0 (including)2019-11-25-staging0 (including)
Wire-webappWire2019-11-26-production0 (including)2019-11-26-production0 (including)
Wire-webappWire2019-12-12-staging0 (including)2019-12-12-staging0 (including)
Wire-webappWire2019-12-20-staging0 (including)2019-12-20-staging0 (including)
Wire-webappWire2020-01-06-production0 (including)2020-01-06-production0 (including)
Wire-webappWire2020-01-09-staging0 (including)2020-01-09-staging0 (including)
Wire-webappWire2020-01-13-production0 (including)2020-01-13-production0 (including)
Wire-webappWire2020-01-15-staging0 (including)2020-01-15-staging0 (including)
Wire-webappWire2020-01-16-staging0 (including)2020-01-16-staging0 (including)
Wire-webappWire2020-01-17-staging0 (including)2020-01-17-staging0 (including)
Wire-webappWire2020-01-21-staging0 (including)2020-01-21-staging0 (including)
Wire-webappWire2020-01-22-production0 (including)2020-01-22-production0 (including)
Wire-webappWire2020-02-06-staging0 (including)2020-02-06-staging0 (including)
Wire-webappWire2020-02-11-staging0 (including)2020-02-11-staging0 (including)
Wire-webappWire2020-02-11-staging1 (including)2020-02-11-staging1 (including)
Wire-webappWire2020-02-14-production0 (including)2020-02-14-production0 (including)
Wire-webappWire2020-02-18-staging0 (including)2020-02-18-staging0 (including)
Wire-webappWire2020-02-20-staging0 (including)2020-02-20-staging0 (including)
Wire-webappWire2020-02-24-staging0 (including)2020-02-24-staging0 (including)
Wire-webappWire2020-02-26-staging0 (including)2020-02-26-staging0 (including)
Wire-webappWire2020-02-28-staging0 (including)2020-02-28-staging0 (including)
Wire-webappWire2020-03-03-production0 (including)2020-03-03-production0 (including)
Wire-webappWire2020-03-03-staging0 (including)2020-03-03-staging0 (including)
Wire-webappWire2020-03-06-staging0 (including)2020-03-06-staging0 (including)
Wire-webappWire2020-03-12-staging0 (including)2020-03-12-staging0 (including)
Wire-webappWire2020-03-18-staging0 (including)2020-03-18-staging0 (including)
Wire-webappWire2020-03-20-staging0 (including)2020-03-20-staging0 (including)
Wire-webappWire2020-03-23-production0 (including)2020-03-23-production0 (including)
Wire-webappWire2020-03-30-staging0 (including)2020-03-30-staging0 (including)
Wire-webappWire2020-04-01-staging0 (including)2020-04-01-staging0 (including)
Wire-webappWire2020-04-07-production0 (including)2020-04-07-production0 (including)
Wire-webappWire2020-04-09-staging0 (including)2020-04-09-staging0 (including)
Wire-webappWire2020-04-16-staging0 (including)2020-04-16-staging0 (including)
Wire-webappWire2020-04-21-production0 (including)2020-04-21-production0 (including)
Wire-webappWire2020-04-22-staging0 (including)2020-04-22-staging0 (including)
Wire-webappWire2020-04-23-staging0 (including)2020-04-23-staging0 (including)
Wire-webappWire2020-04-28-staging0 (including)2020-04-28-staging0 (including)
Wire-webappWire2020-04-29-production0 (including)2020-04-29-production0 (including)
Wire-webappWire2020-05-04-staging0 (including)2020-05-04-staging0 (including)
Wire-webappWire2020-05-06-staging0 (including)2020-05-06-staging0 (including)
Wire-webappWire2020-05-07-production0 (including)2020-05-07-production0 (including)
Wire-webappWire2020-05-07-staging0 (including)2020-05-07-staging0 (including)
Wire-webappWire2020-05-13-staging0 (including)2020-05-13-staging0 (including)
Wire-webappWire2020-05-14-staging0 (including)2020-05-14-staging0 (including)
Wire-webappWire2020-05-15-staging0 (including)2020-05-15-staging0 (including)
Wire-webappWire2020-05-18-staging0 (including)2020-05-18-staging0 (including)
Wire-webappWire2020-05-19-staging0 (including)2020-05-19-staging0 (including)
Wire-webappWire2020-05-20-production0 (including)2020-05-20-production0 (including)
Wire-webappWire2020-05-22-staging0 (including)2020-05-22-staging0 (including)
Wire-webappWire2020-05-26-staging0 (including)2020-05-26-staging0 (including)
Wire-webappWire2020-05-27-staging0 (including)2020-05-27-staging0 (including)
Wire-webappWire2020-05-28-staging0 (including)2020-05-28-staging0 (including)
Wire-webappWire2020-05-29-staging0 (including)2020-05-29-staging0 (including)
Wire-webappWire2020-06-02-production0 (including)2020-06-02-production0 (including)
Wire-webappWire2020-06-05-staging0 (including)2020-06-05-staging0 (including)
Wire-webappWire2020-06-08-staging0 (including)2020-06-08-staging0 (including)
Wire-webappWire2020-06-10-staging0 (including)2020-06-10-staging0 (including)
Wire-webappWire2020-06-12-staging0 (including)2020-06-12-staging0 (including)
Wire-webappWire2020-06-15-production0 (including)2020-06-15-production0 (including)
Wire-webappWire2020-06-15-staging0 (including)2020-06-15-staging0 (including)
Wire-webappWire2020-06-19-staging0 (including)2020-06-19-staging0 (including)
Wire-webappWire2020-06-24-production0 (including)2020-06-24-production0 (including)
Wire-webappWire2020-06-29-staging0 (including)2020-06-29-staging0 (including)
Wire-webappWire2020-07-07-staging0 (including)2020-07-07-staging0 (including)
Wire-webappWire2020-07-07-staging1 (including)2020-07-07-staging1 (including)
Wire-webappWire2020-07-13-staging0 (including)2020-07-13-staging0 (including)
Wire-webappWire2020-07-16-staging0 (including)2020-07-16-staging0 (including)
Wire-webappWire2020-07-24-production0 (including)2020-07-24-production0 (including)
Wire-webappWire2020-07-24-staging0 (including)2020-07-24-staging0 (including)
Wire-webappWire2020-07-24-staging1 (including)2020-07-24-staging1 (including)
Wire-webappWire2020-08-06-staging0 (including)2020-08-06-staging0 (including)
Wire-webappWire2020-08-12-staging0 (including)2020-08-12-staging0 (including)
Wire-webappWire2020-08-12-staging1 (including)2020-08-12-staging1 (including)
Wire-webappWire2020-08-14-staging0 (including)2020-08-14-staging0 (including)
Wire-webappWire2020-08-18-staging0 (including)2020-08-18-staging0 (including)
Wire-webappWire2020-08-19-staging0 (including)2020-08-19-staging0 (including)
Wire-webappWire2020-08-21-staging0 (including)2020-08-21-staging0 (including)
Wire-webappWire2020-08-25-staging0 (including)2020-08-25-staging0 (including)
Wire-webappWire2020-08-26-production0 (including)2020-08-26-production0 (including)
Wire-webappWire2020-09-02-staging0 (including)2020-09-02-staging0 (including)
Wire-webappWire2020-09-03-staging0 (including)2020-09-03-staging0 (including)
Wire-webappWire2020-09-04-staging0 (including)2020-09-04-staging0 (including)
Wire-webappWire2020-09-08-staging0 (including)2020-09-08-staging0 (including)
Wire-webappWire2020-09-11-production0 (including)2020-09-11-production0 (including)
Wire-webappWire2020-09-17-staging0 (including)2020-09-17-staging0 (including)
Wire-webappWire2020-09-18-staging0 (including)2020-09-18-staging0 (including)
Wire-webappWire2020-09-21-production0 (including)2020-09-21-production0 (including)
Wire-webappWire2020-09-28-staging0 (including)2020-09-28-staging0 (including)
Wire-webappWire2020-09-29-production0 (including)2020-09-29-production0 (including)
Wire-webappWire2020-10-01-staging0 (including)2020-10-01-staging0 (including)
Wire-webappWire2020-10-06-staging0 (including)2020-10-06-staging0 (including)
Wire-webappWire2020-10-07-production0 (including)2020-10-07-production0 (including)
Wire-webappWire2020-10-07-staging0 (including)2020-10-07-staging0 (including)
Wire-webappWire2020-10-08-production0 (including)2020-10-08-production0 (including)
Wire-webappWire2020-10-14-staging0 (including)2020-10-14-staging0 (including)
Wire-webappWire2020-10-15-staging0 (including)2020-10-15-staging0 (including)
Wire-webappWire2020-10-21-staging0 (including)2020-10-21-staging0 (including)
Wire-webappWire2020-10-21-staging1 (including)2020-10-21-staging1 (including)
Wire-webappWire2020-10-26-staging0 (including)2020-10-26-staging0 (including)
Wire-webappWire2020-10-27-staging0 (including)2020-10-27-staging0 (including)
Wire-webappWire2020-10-28-production0 (including)2020-10-28-production0 (including)
Wire-webappWire2020-11-09-production0 (including)2020-11-09-production0 (including)
Wire-webappWire2020-11-30-production0 (including)2020-11-30-production0 (including)
Wire-webappWire2020-11-30-staging0 (including)2020-11-30-staging0 (including)
Wire-webappWire2020-12-10-staging0 (including)2020-12-10-staging0 (including)
Wire-webappWire2020-12-14-production0 (including)2020-12-14-production0 (including)
Wire-webappWire2021-01-18-production0 (including)2021-01-18-production0 (including)
Wire-webappWire2021-01-18-staging1 (including)2021-01-18-staging1 (including)
Wire-webappWire2021-01-27-staging0 (including)2021-01-27-staging0 (including)
Wire-webappWire2021-02-02-production0 (including)2021-02-02-production0 (including)
Wire-webappWire2021-02-03-staging0 (including)2021-02-03-staging0 (including)
Wire-webappWire2021-02-04-staging0 (including)2021-02-04-staging0 (including)
Wire-webappWire2021-02-15-staging0 (including)2021-02-15-staging0 (including)
Wire-webappWire2021-02-17-production0 (including)2021-02-17-production0 (including)
Wire-webappWire2021-02-18-staging0 (including)2021-02-18-staging0 (including)
Wire-webappWire2021-02-22-staging1 (including)2021-02-22-staging1 (including)
Wire-webappWire2021-02-26-staging0 (including)2021-02-26-staging0 (including)
Wire-webappWire2021-03-04-production0 (including)2021-03-04-production0 (including)
Wire-webappWire2021-03-05-staging0 (including)2021-03-05-staging0 (including)
Wire-webappWire2021-03-10-staging0 (including)2021-03-10-staging0 (including)
Wire-webappWire2021-03-15-production0 (including)2021-03-15-production0 (including)
Wire-webappWire2021-03-18-staging0 (including)2021-03-18-staging0 (including)
Wire-webappWire2021-03-24-staging0 (including)2021-03-24-staging0 (including)
Wire-webappWire2021-03-25-staging0 (including)2021-03-25-staging0 (including)
Wire-webappWire2021-04-01-production0 (including)2021-04-01-production0 (including)
Wire-webappWire2021-04-06-staging0 (including)2021-04-06-staging0 (including)
Wire-webappWire2021-04-15-staging0 (including)2021-04-15-staging0 (including)
Wire-webappWire2021-04-26-staging0 (including)2021-04-26-staging0 (including)
Wire-webappWire2021-04-28-staging0 (including)2021-04-28-staging0 (including)
Wire-webappWire2021-05-06-staging0 (including)2021-05-06-staging0 (including)
Wire-webappWire2021-05-10-production0 (including)2021-05-10-production0 (including)
Wire-webappWire2021-05-27-staging0 (including)2021-05-27-staging0 (including)
Wire-webappWire2021-06-01-production0 (including)2021-06-01-production0 (including)
Wire-webappWire2021-06-17-staging0 (including)2021-06-17-staging0 (including)
Wire-webappWire2021-07-09-staging0 (including)2021-07-09-staging0 (including)
Wire-webappWire2021-07-26-staging0 (including)2021-07-26-staging0 (including)
Wire-webappWire2021-07-27-staging0 (including)2021-07-27-staging0 (including)
Wire-webappWire2021-08-03-staging0 (including)2021-08-03-staging0 (including)
Wire-webappWire2021-08-04-staging0 (including)2021-08-04-staging0 (including)
Wire-webappWire2021-08-09-staging0 (including)2021-08-09-staging0 (including)
Wire-webappWire2021-08-17-staging0 (including)2021-08-17-staging0 (including)
Wire-webappWire2021-08-25-staging0 (including)2021-08-25-staging0 (including)
Wire-webappWire2021-08-25-staging1 (including)2021-08-25-staging1 (including)
Wire-webappWire2021-08-27-staging0 (including)2021-08-27-staging0 (including)
Wire-webappWire2021-08-30-production0 (including)2021-08-30-production0 (including)
Wire-webappWire2021-08-30-staging0 (including)2021-08-30-staging0 (including)
Wire-webappWire2021-09-03-staging0 (including)2021-09-03-staging0 (including)
Wire-webappWire2021-09-06-staging0 (including)2021-09-06-staging0 (including)
Wire-webappWire2021-09-06-staging1 (including)2021-09-06-staging1 (including)
Wire-webappWire2021-09-06-staging2 (including)2021-09-06-staging2 (including)
Wire-webappWire2021-09-06-staging3 (including)2021-09-06-staging3 (including)
Wire-webappWire2021-09-08-staging0 (including)2021-09-08-staging0 (including)
Wire-webappWire2021-09-09-staging0 (including)2021-09-09-staging0 (including)
Wire-webappWire2021-09-10-staging0 (including)2021-09-10-staging0 (including)
Wire-webappWire2021-09-13-production0 (including)2021-09-13-production0 (including)
Wire-webappWire2021-09-13-staging0 (including)2021-09-13-staging0 (including)
Wire-webappWire2021-09-20-staging0 (including)2021-09-20-staging0 (including)
Wire-webappWire2021-09-22-staging0 (including)2021-09-22-staging0 (including)
Wire-webappWire2021-09-27-production0 (including)2021-09-27-production0 (including)
Wire-webappWire2021-09-29-staging0 (including)2021-09-29-staging0 (including)
Wire-webappWire2021-09-30-staging0 (including)2021-09-30-staging0 (including)
Wire-webappWire2021-10-02-staging0 (including)2021-10-02-staging0 (including)
Wire-webappWire2021-10-04-production0 (including)2021-10-04-production0 (including)
Wire-webappWire2021-10-13-staging0 (including)2021-10-13-staging0 (including)
Wire-webappWire2021-10-20-staging0 (including)2021-10-20-staging0 (including)
Wire-webappWire2021-10-27-staging0 (including)2021-10-27-staging0 (including)
Wire-webappWire2021-11-01-production0 (including)2021-11-01-production0 (including)
Wire-webappWire2021-11-25-staging0 (including)2021-11-25-staging0 (including)
Wire-webappWire2021-12-01-production0 (including)2021-12-01-production0 (including)
Wire-webappWire2021-12-01-staging0 (including)2021-12-01-staging0 (including)
Wire-webappWire2021-12-02-production0 (including)2021-12-02-production0 (including)

Extended Description

Resources that may contain sensitive data include documents, packets, messages, databases, etc. While this data may be useful to an individual user or small set of users who share the resource, it may need to be removed before the resource can be shared outside of the trusted group. The process of removal is sometimes called cleansing or scrubbing. For example, a product for editing documents might not remove sensitive data such as reviewer comments or the local pathname where the document is stored. Or, a proxy might not remove an internal IP address from headers before making an outgoing request to an Internet site.

Potential Mitigations

  • Compartmentalize the system to have “safe” areas where trust boundaries can be unambiguously drawn. Do not allow sensitive data to go outside of the trust boundary and always be careful when interfacing with a compartment outside of the safe area.

  • Ensure that appropriate compartmentalization is built into the system design, and the compartmentalization allows for and reinforces privilege separation functionality. Architects and designers should rely on the principle of least privilege to decide the appropriate time to use privileges and the time to drop privileges.

  • Some tools can automatically analyze documents to redact, strip, or “sanitize” private information, although some human review might be necessary. Tools may vary in terms of which document formats can be processed.

  •     When calling an external program to automatically
        generate or convert documents, invoke the program with
        any available options that avoid generating sensitive
        metadata.  Some formats have well-defined fields that
        could contain private data, such as Exchangeable image
        file format (Exif), which can contain potentially
        sensitive metadata such as geolocation, date, and time
        [REF-1515] [REF-1516].
    

References