Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.
                
            References
                    | Link | Resource | 
|---|---|
| https://github.com/nextcloud/spreed/issues/7048 | Exploit Issue Tracking Third Party Advisory | 
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vxpr-hcqq-7fw7 | Third Party Advisory | 
| https://github.com/nextcloud/spreed/pull/7092 | Patch Third Party Advisory | 
| https://github.com/nextcloud/spreed/pull/7034 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
                                
                                
  | 
                        
Information
                Published : 2022-05-17 12:15
Updated : 2022-05-26 08:21
NVD link : CVE-2022-24890
Mitre link : CVE-2022-24890
JSON object : View
CWE
                
                    
                        
                        CWE-276
                        
            Incorrect Default Permissions
Products Affected
                nextcloud
- talk
 


