-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathTelegram:CVE-2021-2735.html
More file actions
30 lines (30 loc) · 1.05 KB
/
Copy pathTelegram:CVE-2021-2735.html
File metadata and controls
30 lines (30 loc) · 1.05 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
<html>
<body>
<p>Hi World,<br>
<br>
Please refer minimal poc for my discovered CVE-2021-27351 in Telegram Android 7.2.1 & earlier - Telegram Desktop (Unix, Windows) 2.4.7 & earlier<br>
<br>
<br>
<b>[ Description]</b><br>
<b>Telegram CVE-2021-27351 Insecure session termination</b><br>
The Terminate Session feature in the Telegram application through 7.2.1 for Android, and <br>
through 2.4.7 for Windows and UNIX, failed to invalidate a recently active session.<br>
<br>
<br>
------------------------------------------<br>
<b>[VulnerabilityType Other]</b><br>
Insecure session termination<br>
------------------------------------------<br>
<b>[Vendor of Product]</b><br>
Telegram<br>
------------------------------------------<br>
<br>
<b>[Affected Product Code Base]</b><br>
Telegram Android 7.2.1 & earlier - Telegram Desktop (Unix, Windows) 2.4.7 & earlier<br>
<br>
------------------------------------------<br>
<br>
Connect with me for more details on attack vector at <a href="https://in.linkedin.com/in/vijay-tikudave">Vijay Tikudave</a><br>
</p>
</body>
</html>