PT-2023-22767 · Nextcloud · Nextcloud Talk

·

CVE-2023-30540

·

Published

2023-04-17

·

Updated

2023-04-27

CVSS v3.1

3.5

Low

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Talk versions prior to 15.0.5
Description The issue allows a user added later to a conversation to access data that was deleted before they were added. This is a problem in Nextcloud Talk, a chat, video, and audio call extension for Nextcloud.
Recommendations For versions prior to 15.0.5, upgrade to version 15.0.5 to resolve the issue. As a temporary workaround, consider restricting access to conversations that contain sensitive or deleted data until the upgrade is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-30540
GHSA-C9HR-CQ65-9MJW

Affected Products

Nextcloud Talk