PT-2022-24813 · Nextcloud · Nextcloud Talk
Nickvergessen
·
Published
2022-09-16
·
Updated
2022-09-21
·
CVE-2022-39212
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Talk versions prior to 13.0.8
Nextcloud Talk versions prior to 14.0.4
Description
The issue allows an attacker to see the last video frame of any participant who has video disabled but a camera selected.
Recommendations
For versions prior to 13.0.8, upgrade to 13.0.8.
For versions prior to 14.0.4, upgrade to 14.0.4.
As a temporary workaround for users unable to upgrade, select
None as camera before joining the call.Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud Talk