PT-2022-16957 · Nextcloud · Nextcloud Talk

Ctulhu

·

Published

2022-04-27

·

Updated

2022-05-09

·

CVE-2022-24887

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Talk versions prior to 11.3.4 Nextcloud Talk versions prior to 12.2.2 Nextcloud Talk versions prior to 13.0.0
Description The issue affects Nextcloud Talk, a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. When sharing a Deck card in conversation, the metaData can be manipulated, allowing users to be tricked into opening arbitrary URLs.
Recommendations For versions prior to 11.3.4, update to version 11.3.4 or later. For versions prior to 12.2.2, update to version 12.2.2 or later. For versions prior to 13.0.0, update to version 13.0.0 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24887
GHSA-J45W-7MPQ-264C

Affected Products

Nextcloud Talk