VulnerabilityModified
CVE-2022-22845
QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.
CRITICAL 9.8EPSS 3.81%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.81%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.81% probability · 89th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-798
- Affected
- qxip/homer webapp
- Source
- cve@mitre.org
References
- http://sipcapture.orgVendor Advisory
- https://github.com/sipcapture/homerThird Party Advisory
- https://github.com/sipcapture/homer-app/commit/7f92f3afc8b0380c14af3d0fc1c365318a2d1591Patch, Third Party Advisory
- https://github.com/sipcapture/homer-app/compare/1.4.27...1.4.28Patch, Third Party Advisory
- http://sipcapture.orgVendor Advisory
- https://github.com/sipcapture/homerThird Party Advisory
- https://github.com/sipcapture/homer-app/commit/7f92f3afc8b0380c14af3d0fc1c365318a2d1591Patch, Third Party Advisory
- https://github.com/sipcapture/homer-app/compare/1.4.27...1.4.28Patch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.