PT-2023-18520 · Nextcloud · Deck

·

CVE-2023-22469

·

Publicado

2023-01-10

·

Atualizado

2023-01-14

CVSS v3.1

5.8

Média

VetorAV:N/AC:H/PR:L/UI:R/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud app Deck versions prior to 1.8.2
Description The issue affects Deck, a kanban style organization tool integrated with Nextcloud, used for personal planning and project organization for teams. When getting the reference preview for Deck cards the user has no access to, an unauthorized user could eventually get the cached data of a user that has access. There are currently no known workarounds.
Recommendations For versions prior to 1.8.2, it is recommended that the Nextcloud app Deck is upgraded to 1.8.2.

Exploit

Correção

Insecure Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-22469
GHSA-8FJP-W9GP-J5HQ

Produtos afetados

Deck