PT-2023-18524 · Nextcloud · Nextcloud Desktop Client

Nickvergessen

·

Published

2023-01-09

·

Updated

2023-01-13

·

CVE-2023-22472

CVSS v3.1

5.3

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop client versions prior to 3.6.2
Description The issue affects Deck, a kanban style organization tool integrated with Nextcloud, allowing an attacker to make a user send any POST request with an arbitrary body if they click on a malicious deep link on a Windows computer. This could be done through various means such as email or chat links. There are no known workarounds for this issue.
Recommendations For versions prior to 3.6.2, upgrade the Nextcloud Desktop client to version 3.6.2 to resolve the issue. As a temporary workaround, consider avoiding the use of deep links from untrusted sources until the upgrade is applied.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2023-22472
GHSA-4GFV-XQPX-42QJ

Affected Products

Nextcloud Desktop Client