HIGH🇵🇱 Wersja polska

CVE-2023-39957

CVSS 7.8v3.1pub. 2023-08-10upd. 2024-11-21

Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud Talk Android version 17.0.0 has a patch for this issue. No known workarounds are available.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Nextcloud Talk

    APP
    Nextcloud
    17.0.0< 17.0.0
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2020-8180CRITICAL9.9PL ✓same product

Code injection w Nextcloud Talk przez niesanityzowane komendy administratora

CVE-2021-32689HIGH8.1same product

Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2,...

CVE-2023-45149MEDIUM4.3same product

Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection...

CVE-2022-39212MEDIUM4.3same product

Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected vers...

CVE-2022-24887MEDIUM4.3same product

Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior...