CVE-2022-24906 Information
Jun 07, 2022
cve
Description
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11 1.4.6 or 1.5.4. There is no workaround available.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://github.com/nextcloud/deck/pull/3384 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hx9w-xfrg-2qvp https://hackerone.com/reports/1354334
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: