PT-2022-16961 · Nextcloud · Nextcloud Talk
Nickvergessen
·
Published
2022-05-17
·
Updated
2022-05-26
·
CVE-2022-24890
CVSS v2.0
3.5
Low
| Vector | AV:N/AC:M/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Talk versions prior to 13.0.5
Nextcloud Talk versions prior to 14.0.0
Description
The issue affects Nextcloud Talk, a video and audio conferencing app for Nextcloud. A call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions.
Recommendations
For versions prior to 13.0.5, update to version 13.0.5 to resolve the issue.
For versions prior to 14.0.0, update to version 14.0.0 to resolve the issue.
Exploit
Fix
Incorrect Default Permissions
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Talk