PT-2022-28125 · Instedd · Instedd Nuntium

Published

2022-12-28

·

Updated

2024-05-17

·

CVE-2022-4823

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions InSTEDD Nuntium (affected versions not specified)
Description A problematic issue was found in InSTEDD Nuntium, affecting an unknown function of the file app/controllers/geopoll controller.rb. The manipulation of the signature argument leads to observable timing discrepancy. It is possible to launch the attack remotely.
Recommendations To fix this issue, it is recommended to apply a patch with the name 77236f7fd71a0e2eefeea07f9866b069d612cf0d. As a temporary workaround, consider restricting access to the geopoll controller.rb file until a patch is applied.

Fix

Side Channel Attack

Weakness Enumeration

Related Identifiers

CVE-2022-4823

Affected Products

Instedd Nuntium