CVE-2023-28845
31.03.2023, 23:15
Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members. It is recommended that the Nextcloud Talk is upgraded to 14.0.9 or 15.0.4. There are no known workarounds for this vulnerability.Enginsight
| Vendor | Product | Version |
|---|---|---|
| nextcloud | talk | 14.0.0 ≤ 𝑥 < 14.0.9 |
| nextcloud | talk | 15.0.0 ≤ 𝑥 < 15.0.4 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration