PT-2022-16957 · Nextcloud · Nextcloud Talk
Ctulhu
·
Published
2022-04-27
·
Updated
2022-05-09
·
CVE-2022-24887
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Talk versions prior to 11.3.4
Nextcloud Talk versions prior to 12.2.2
Nextcloud Talk versions prior to 13.0.0
Description
The issue affects Nextcloud Talk, a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. When sharing a Deck card in conversation, the metaData can be manipulated, allowing users to be tricked into opening arbitrary URLs.
Recommendations
For versions prior to 11.3.4, update to version 11.3.4 or later.
For versions prior to 12.2.2, update to version 12.2.2 or later.
For versions prior to 13.0.0, update to version 13.0.0 or later.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud Talk