Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the Nextcloud Deck app is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vw5-pfg6-3wm6 | Third Party Advisory |
| https://github.com/nextcloud/deck/pull/4173 | Patch Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2023-01-13 17:15
Updated : 2023-01-24 10:38
NVD link : CVE-2023-22471
Mitre link : CVE-2023-22471
JSON object : View
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
Products Affected
nextcloud
- deck


