CVE-2022-24906

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.
References
Link Resource
https://github.com/nextcloud/deck/pull/3384 Issue Tracking Patch Third Party Advisory
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hx9w-xfrg-2qvp Exploit Issue Tracking Third Party Advisory
https://hackerone.com/reports/1354334 Exploit Issue Tracking Third Party Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*

Information

Published : 2022-05-20 09:15

Updated : 2022-06-02 07:19


NVD link : CVE-2022-24906

Mitre link : CVE-2022-24906


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

nextcloud

  • deck