PT-2022-28125 · Instedd · Instedd Nuntium

CVE-2022-4823

·

Published

2022-12-28

·

Updated

2024-05-17

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions InSTEDD Nuntium (affected versions not specified)
Description A problematic issue was found in InSTEDD Nuntium, affecting an unknown function of the file app/controllers/geopoll controller.rb. The manipulation of the signature argument leads to observable timing discrepancy. It is possible to launch the attack remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name 77236f7fd71a0e2eefeea07f9866b069d612cf0d. As a temporary workaround, consider restricting access to the geopoll controller.rb file until a patch is applied.

Exploit

Fix

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-4823

Affected Products

Instedd Nuntium