PT-2022-16975 · Nextcloud · Nextcloud Deck
Ctulhu
·
Published
2022-05-20
·
Updated
2023-07-06
·
CVE-2022-24906
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Deck versions prior to 1.2.11
Nextcloud Deck versions prior to 1.4.6
Nextcloud Deck versions prior to 1.5.4
Description
Nextcloud Deck is a Kanban-style project and personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users.
Recommendations
For versions prior to 1.2.11, upgrade to 1.2.11.
For versions prior to 1.4.6, upgrade to 1.4.6.
For versions prior to 1.5.4, upgrade to 1.5.4.
Exploit
Fix
Generation of Error Message Containing Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Deck