Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. When getting the reference preview for Deck cards the user has no access to, unauthorized user could eventually get the cached data of a user that has access. There are currently no known workarounds. It is recommended that the Nextcloud app Deck is upgraded to 1.8.2.
References
Link | Resource |
---|---|
https://github.com/nextcloud/deck/pull/4196 | Patch Third Party Advisory |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-8fjp-w9gp-j5hq | Exploit Patch Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-01-10T20:26:27.108Z
Updated:
Reserved: 2022-12-29T03:00:40.880Z
Link: CVE-2023-22469
JSON object: View
NVD Information
Status : Modified
Published: 2023-01-10T21:15:12.830
Modified: 2023-11-07T04:06:57.603
Link: CVE-2023-22469
JSON object: View
Redhat Information
No data.
CWE