Lucene search

K
nextcloudNextcloudGHSA-J53P-R755-V4JF
HistoryFeb 27, 2023 - 3:42 p.m.

Messages can still be seen on conversation after expiring when cron is misconfigured

2023-02-2715:42:13
github.com
14
nextcloud talk
misconfiguration
cron job
api
expired messages
frontend code

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

30.3%

Description

Impact

When cron jobs were misconfigured and therefore messages are not expired, the API would still return them while they were then hidden by the frontend code.

Patches

It is recommended that the Nextcloud Talk is upgraded to 15.0.3

Workarounds

  • No workaround available

References

For more information

If you have any questions or comments about this advisory:

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

EPSS

0.001

Percentile

30.3%

Related for GHSA-J53P-R755-V4JF