CVE-2023-22471
14.01.2023, 01:15
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the Nextcloud Deck app is upgraded to 1.6.5 or 1.7.3 or 1.8.2.Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | deck | 𝑥 < 1.6.5 |
nextcloud | deck | 1.7.0 ≤ 𝑥 < 1.7.3 |
nextcloud | deck | 1.8.0 ≤ 𝑥 < 1.8.2 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration