Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.
References
Link Resource
https://github.com/nextcloud/deck/pull/3384 Issue Tracking Patch Third Party Advisory
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hx9w-xfrg-2qvp Exploit Issue Tracking Third Party Advisory
https://hackerone.com/reports/1354334 Exploit Issue Tracking Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: GitHub_M

Published: 2022-05-20T15:40:17

Updated: 2022-05-20T15:40:17

Reserved: 2022-02-10T00:00:00


Link: CVE-2022-24906

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-05-20T16:15:09.193

Modified: 2023-07-06T13:36:25.520


Link: CVE-2022-24906

JSON object: View

cve-icon Redhat Information

No data.