wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletion. This is the case for both temporary clients (marking the device as a public computer on login) and regular clients instructing the deletion of all personal information and conversations upon logout. Access to the machine is required to access the data. If encryption-at-rest is used, cryptographic material can't be exported. The underlying issue has been fixed with wire-webapp version 2025-05-14-production.0. In order to mitigate potential impact, the database must be manually deleted on devices where the option "This is a public computer" was used prior to log in or a log out with the request to delete local data with the affected versions has happened before.
History

Fri, 30 May 2025 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Wire
Wire wire-webapp
Weaknesses CWE-212
CPEs cpe:2.3:a:wire:wire-webapp:2025-04-14:production0:*:*:*:*:*:*
cpe:2.3:a:wire:wire-webapp:2025-04-29:production0:*:*:*:*:*:*
cpe:2.3:a:wire:wire-webapp:2025-05-06:alphaging0:*:*:*:*:*:*
Vendors & Products Wire
Wire wire-webapp

Thu, 22 May 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 22 May 2025 17:45:00 +0000

Type Values Removed Values Added
Description wire-webapp is the web application for the open-source messaging service Wire. A bug fix caused a regression causing an issue with function to delete local data. Instructing the client to delete its local database on user logout does not result in deletion. This is the case for both temporary clients (marking the device as a public computer on login) and regular clients instructing the deletion of all personal information and conversations upon logout. Access to the machine is required to access the data. If encryption-at-rest is used, cryptographic material can't be exported. The underlying issue has been fixed with wire-webapp version 2025-05-14-production.0. In order to mitigate potential impact, the database must be manually deleted on devices where the option "This is a public computer" was used prior to log in or a log out with the request to delete local data with the affected versions has happened before.
Title wire-webapp has no database deletion on client logout
Weaknesses CWE-226
References
Metrics cvssV3_1

{'score': 6, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-05-22T17:20:26.910Z

Updated: 2025-05-22T17:59:44.874Z

Reserved: 2025-05-15T16:06:40.941Z

Link: CVE-2025-48066

cve-icon Vulnrichment

Updated: 2025-05-22T17:42:13.319Z

cve-icon NVD

Status : Analyzed

Published: 2025-05-22T18:15:43.027

Modified: 2025-05-30T01:18:41.410

Link: CVE-2025-48066

cve-icon Redhat

No data.