PT-2023-20444 · Nextcloud · Nextcloud Talk

Ctulhu

·

Published

2023-02-27

·

Updated

2023-03-08

·

CVE-2023-26041

CVSS v3.1

2.6

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Talk versions prior to 15.0.3
Description Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured, messages were not expired, and the API would still return them while they were hidden by the frontend code.
Recommendations For versions prior to 15.0.3, upgrade to version 15.0.3 to resolve the issue. As a temporary workaround, consider configuring cron jobs properly to expire messages, until a patch is available.

Exploit

Fix

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

CVE-2023-26041
GHSA-J53P-R755-V4JF

Affected Products

Nextcloud Talk