Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-28845: Chat room membership disclosed via autocompletion when not a member yourself

Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members. It is recommended that the Nextcloud Talk is upgraded to 14.0.9 or 15.0.4. There are no known workarounds for this vulnerability.

CVE
#vulnerability#perl

Affected versions

>= 14.0.0, >= 15.0.0

Patched versions

14.0.9, 15.0.4

Description

Impact

An attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members.

Patches

It is recommended that the Nextcloud Talk is upgraded to 14.0.9 or 15.0.4

Workarounds

  • No workaround available

References

  • HackerOne
  • PullRequest

For more information

If you have any questions or comments about this advisory:

  • Create a post in nextcloud/security-advisories
  • Customers: Open a support ticket at support.nextcloud.com

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907