VulnerabilityModified
CVE-2022-24906
The full path of the application is exposed to unauthorized users.
MEDIUM 4.3EPSS 1.06%
Does this matter?
Lower severity and a low EPSS score (1.06%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 1.06% probability · 63th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200, CWE-209
- Affected
- nextcloud/deck
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/deck/pull/3384Issue Tracking, Patch, Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hx9w-xfrg-2qvpExploit, Issue Tracking, Third Party Advisory
- https://hackerone.com/reports/1354334Exploit, Issue Tracking, Third Party Advisory
- https://github.com/nextcloud/deck/pull/3384Issue Tracking, Patch, Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hx9w-xfrg-2qvpExploit, Issue Tracking, Third Party Advisory
- https://hackerone.com/reports/1354334Exploit, Issue Tracking, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.