CVE-2022-24890
17.05.2022, 19:15
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | talk | 𝑥 < 13.0.5 |
nextcloud | talk | 14.0.0:beta1 |
nextcloud | talk | 14.0.0:rc1 |
nextcloud | talk | 14.0.0:rc2 |
nextcloud | talk | 14.0.0:rc3 |
nextcloud | talk | 14.0.0:rc4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-200 - Exposure of Sensitive Information to an Unauthorized ActorThe product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
- CWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.
References