CVE-2022-4823

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-4823
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-4823.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-4823
Published
2022-12-28T21:15:11Z
Modified
2025-01-15T04:27:09.427231Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

A vulnerability, which was classified as problematic, was found in InSTEDD Nuntium. Affected is an unknown function of the file app/controllers/geopoll_controller.rb. The manipulation of the argument signature leads to observable timing discrepancy. It is possible to launch the attack remotely. The name of the patch is 77236f7fd71a0e2eefeea07f9866b069d612cf0d. It is recommended to apply a patch to fix this issue. VDB-217002 is the identifier assigned to this vulnerability.

References

Affected packages

Git / github.com/instedd/nuntium

Affected ranges

Type
GIT
Repo
https://github.com/instedd/nuntium
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

1.*

1.10
1.10-pre1
1.10-pre2
1.10-pre3
1.10-pre4
1.10.1
1.10.2
1.10.3
1.10.4
1.10.5
1.11.0
1.11.1
1.12.0
1.12.1
1.5
1.5.1
1.6
1.6-pre1
1.6-pre2
1.7
1.7-pre1
1.8
1.8.1
1.8.2
1.8.3
1.8.4
1.9
1.9-pre1
1.9-pre2
1.9-pre3
1.9-pre4
1.9-pre5
1.9.1
1.9.2