PT-2022-16975 · Nextcloud · Nextcloud Deck

Ctulhu

·

Published

2022-05-20

·

Updated

2023-07-06

·

CVE-2022-24906

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Deck versions prior to 1.2.11 Nextcloud Deck versions prior to 1.4.6 Nextcloud Deck versions prior to 1.5.4
Description Nextcloud Deck is a Kanban-style project and personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users.
Recommendations For versions prior to 1.2.11, upgrade to 1.2.11. For versions prior to 1.4.6, upgrade to 1.4.6. For versions prior to 1.5.4, upgrade to 1.5.4.

Exploit

Fix

Generation of Error Message Containing Sensitive Information

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2022-24906
GHSA-HX9W-XFRG-2QVP

Affected Products

Nextcloud Deck