MEDIUM🇵🇱 Wersja polska

CVE-2023-45149

CVSS 4.3v3.1pub. 2023-10-16upd. 2024-11-21

Nextcloud talk is a chat module for the Nextcloud server platform. In affected versions brute force protection of public talk conversation passwords can be bypassed, as there was an endpoint validating the conversation password without registering bruteforce attempts. It is recommended that the Nextcloud Talk app is upgraded to 15.0.8, 16.0.6 or 17.1.1. There are no known workarounds for this vulnerability.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
  • Nextcloud Talk

    APP
    Nextcloud
    15.0.0 – 15.0.8 (excl.)16.0.0 – 16.0.6 (excl.)17.0.0 – 17.1.1 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2020-8180CRITICAL9.9PL ✓same product

Code injection w Nextcloud Talk przez niesanityzowane komendy administratora

CVE-2023-39957HIGH7.8same product

Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to vers...

CVE-2021-32689HIGH8.1same product

Nextcloud Talk is a fully on-premises audio/video and chat communication service. In versions prior to 11.2.2,...

CVE-2022-39212MEDIUM4.3same product

Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected vers...

CVE-2022-24887MEDIUM4.3same product

Nextcloud Talk is a video and audio conferencing app for Nextcloud, a self-hosted productivity platform. Prior...