PT-2022-11371 · Nextcloud · Nextcloud Talk

Ctulhu

·

Published

2022-03-08

·

Updated

2022-03-15

·

CVE-2021-41180

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Talk versions prior to 12.1.2
Description Nextcloud talk is a self-hosting messaging service. In affected versions, an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user interaction. This only affected users of the Android Talk client.
Recommendations For versions prior to 12.1.2, it is recommended that the Nextcloud Talk App is upgraded to 12.1.2. As a temporary workaround, consider restricting the use of geolocation previews in the Nextcloud Talk application until a patch is available. Avoid using the geolocation preview feature in the affected Android Talk client until the issue is resolved.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41180
GHSA-4FXR-MRW2-CQ92

Affected Products

Nextcloud Talk