Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.
References
Link | Resource |
---|---|
https://github.com/nextcloud/spreed/issues/7048 | Exploit Issue Tracking Third Party Advisory |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vxpr-hcqq-7fw7 | Third Party Advisory |
https://github.com/nextcloud/spreed/pull/7092 | Patch Third Party Advisory |
https://github.com/nextcloud/spreed/pull/7034 | Exploit Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2022-05-17 12:15
Updated : 2022-05-26 08:21
NVD link : CVE-2022-24890
Mitre link : CVE-2022-24890
JSON object : View
CWE
CWE-276
Incorrect Default Permissions
Products Affected
nextcloud
- talk