PT-2022-11371 · Nextcloud · Nextcloud Talk
Ctulhu
·
Published
2022-03-08
·
Updated
2022-03-15
·
CVE-2021-41180
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Talk versions prior to 12.1.2
Description
Nextcloud talk is a self-hosting messaging service. In affected versions, an attacker is able to control the link of a geolocation preview in the Nextcloud Talk application due to a lack of validation on the link. This could result in an open-redirect, but required user interaction. This only affected users of the Android Talk client.
Recommendations
For versions prior to 12.1.2, it is recommended that the Nextcloud Talk App is upgraded to 12.1.2.
As a temporary workaround, consider restricting the use of geolocation previews in the Nextcloud Talk application until a patch is available.
Avoid using the geolocation preview feature in the affected Android Talk client until the issue is resolved.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud Talk