PT-2023-20444 · Nextcloud · Nextcloud Talk
Ctulhu
·
Published
2023-02-27
·
Updated
2023-03-08
·
CVE-2023-26041
CVSS v3.1
2.6
Low
| Vector | AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Talk versions prior to 15.0.3
Description
Nextcloud Talk is a fully on-premises audio/video and chat communication service. When cron jobs were misconfigured, messages were not expired, and the API would still return them while they were hidden by the frontend code.
Recommendations
For versions prior to 15.0.3, upgrade to version 15.0.3 to resolve the issue.
As a temporary workaround, consider configuring cron jobs properly to expire messages, until a patch is available.
Exploit
Fix
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Talk