VulnerabilityModified
CVE-2023-30540
Nextcloud Talk is a chat, video & audio call extension for Nextcloud.
MEDIUM 4.3EPSS 0.66%
Does this matter?
Lower severity and a low EPSS score (0.66%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that users upgrad to 15.0.5. There are no known workarounds for this issue.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.66% probability · 49th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- nextcloud/talk
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-c9hr-cq65-9mjwVendor Advisory
- https://github.com/nextcloud/spreed/pull/8985Patch
- https://hackerone.com/reports/1894676Permissions Required
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-c9hr-cq65-9mjwVendor Advisory
- https://github.com/nextcloud/spreed/pull/8985Patch
- https://hackerone.com/reports/1894676Permissions Required
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.