PT-2023-22767 · Nextcloud · Nextcloud Talk
Hackitbharat
·
Publicado
2023-04-17
·
Atualizado
2023-04-27
·
CVE-2023-30540
CVSS v3.1
3.5
Baixa
| Vetor | AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Talk versions prior to 15.0.5
Description
The issue allows a user added later to a conversation to access data that was deleted before they were added. This is a problem in Nextcloud Talk, a chat, video, and audio call extension for Nextcloud.
Recommendations
For versions prior to 15.0.5, upgrade to version 15.0.5 to resolve the issue.
As a temporary workaround, consider restricting access to conversations that contain sensitive or deleted data until the upgrade is applied.
Exploit
Correção
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Nextcloud Talk