CVE-2022-1252

HIGH

gnuboard <= 5.5.5 - Sensitive Information Exposure via Weak Encryption Algorithm

Title source: llm
STIX 2.1

Description

Use of a Broken or Risky Cryptographic Algorithm in GitHub repository gnuboard/gnuboard5 prior to and including 5.5.5. A vulnerability in gnuboard v5.5.5 and below uses weak encryption algorithms leading to sensitive information exposure. This allows an attacker to derive the email address of any user, including when the 'Let others see my information.' box is ticked off. Or to send emails to any email address, with full control of its contents

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://huntr.dev/bounties/c8c2c3e1-67d0-4a11-a4d4-11af567a9ebb
Exploit, Third Party Advisory x_refsource_misc
https://0g.vc/posts/insecure-cipher-gnuboard5/

Scores

CVSS v3 8.2
EPSS 0.0052
EPSS Percentile 40.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N

Details

CWE
CWE-327
Status published
Products (1)
sir/gnuboard < 5.5.5
Published Apr 11, 2022
Tracked Since Feb 18, 2026