PT-2021-22473 · Nextcloud · Nextcloud Talk
Lukas Reschke
·
Published
2021-11-15
·
Updated
2021-11-17
·
CVE-2021-39222
CVSS v3.1
6.4
Medium
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Talk versions prior to 10.0.7
Nextcloud Talk versions prior to 10.1.4
Nextcloud Talk versions prior to 11.1.2
Nextcloud Talk versions prior to 11.2.0
Nextcloud Talk versions prior to 12.0.0
Description
The Nextcloud Talk application was vulnerable to a stored Cross-Site Scripting (XSS) issue. For exploitation, a user would need to right-click on a malicious file and open the file in a new tab. Due to the strict Content-Security-Policy shipped with Nextcloud, this issue is not exploitable on modern browsers supporting Content-Security-Policy.
Recommendations
For versions prior to 10.0.7, upgrade to version 10.0.7 or later.
For versions prior to 10.1.4, upgrade to version 10.1.4 or later.
For versions prior to 11.1.2, upgrade to version 11.1.2 or later.
For versions prior to 11.2.0, upgrade to version 11.2.0 or later.
For versions prior to 12.0.0, upgrade to version 12.0.0 or later.
As a temporary workaround, consider using a browser that has support for Content-Security-Policy.
Fix
Unrestricted File Upload
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Talk