PT-2023-22767 · Nextcloud · Nextcloud Talk

Hackitbharat

·

Publicado

2023-04-17

·

Atualizado

2023-04-27

·

CVE-2023-30540

CVSS v3.1

3.5

Baixa

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Talk versions prior to 15.0.5
Description The issue allows a user added later to a conversation to access data that was deleted before they were added. This is a problem in Nextcloud Talk, a chat, video, and audio call extension for Nextcloud.
Recommendations For versions prior to 15.0.5, upgrade to version 15.0.5 to resolve the issue. As a temporary workaround, consider restricting access to conversations that contain sensitive or deleted data until the upgrade is applied.

Exploit

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30540
GHSA-C9HR-CQ65-9MJW

Produtos afetados

Nextcloud Talk