SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-30540

Nextcloud Talk is a chat, video & audio call extension for Nextcloud.

MEDIUM 4.3EPSS 0.66%

Does this matter?

Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that users upgrad to 15.0.5. There are no known workarounds for this issue.

CVSS 3.1
4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.66% probability · 49th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
nextcloud/talk
Source
security-advisories@github.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.