PT-2023-22767 · Nextcloud · Nextcloud Talk

Hackitbharat

·

Published

2023-04-17

·

Updated

2023-04-27

·

CVE-2023-30540

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Talk versions prior to 15.0.5
Description The issue allows a user added later to a conversation to access data that was deleted before they were added. This is a problem in Nextcloud Talk, a chat, video, and audio call extension for Nextcloud.
Recommendations For versions prior to 15.0.5, upgrade to version 15.0.5 to resolve the issue. As a temporary workaround, consider restricting access to conversations that contain sensitive or deleted data until the upgrade is applied.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2023-30540
GHSA-C9HR-CQ65-9MJW

Affected Products

Nextcloud Talk