SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-41971

An attacker would be able to see videos on a call in a public conversation after being removed from that conversation, provided that they were removed while being in the call.

MEDIUM 6.5EPSS 0.79%

Does this matter?

Lower severity and a low EPSS score (0.79%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcould Talk android is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0, guests can continue to receive video streams from a call after being removed from a conversation. An attacker would be able to see videos on a call in a public conversation after being removed from that conversation, provided that they were removed while being in the call. Versions 12.2.8, 13.0.10, 14.0.6, and 15.0.0 contain patches for the issue. No known workarounds are available.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.79% probability · 54th percentile
CISA KEV
Not listed
Weakness
CWE-200, CWE-359, CWE-668
Affected
nextcloud/nextcloud talk
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.