Vulnerability Description
QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Qxip | Homer Webapp | < 1.4.28 |
Related Weaknesses (CWE)
References
- http://sipcapture.orgVendor Advisory
- https://github.com/sipcapture/homerThird Party Advisory
- https://github.com/sipcapture/homer-app/commit/7f92f3afc8b0380c14af3d0fc1c365318PatchThird Party Advisory
- https://github.com/sipcapture/homer-app/compare/1.4.27...1.4.28PatchThird Party Advisory
- http://sipcapture.orgVendor Advisory
- https://github.com/sipcapture/homerThird Party Advisory
- https://github.com/sipcapture/homer-app/commit/7f92f3afc8b0380c14af3d0fc1c365318PatchThird Party Advisory
- https://github.com/sipcapture/homer-app/compare/1.4.27...1.4.28PatchThird Party Advisory
FAQ
What is CVE-2022-22845?
CVE-2022-22845 is a vulnerability with a CVSS score of 9.8 (CRITICAL). QXIP SIPCAPTURE homer-app before 1.4.28 for HOMER 7.x has the same 167f0db2-f83e-4baa-9736-d56064a5b415 JWT secret key across different customers' installations.
How severe is CVE-2022-22845?
CVE-2022-22845 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-22845?
Check the references section above for vendor advisories and patch information. Affected products include: Qxip Homer Webapp.