Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the Nextcloud Deck app is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
References
Link | Resource |
---|---|
https://github.com/nextcloud/deck/pull/4173 | Patch Third Party Advisory |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vw5-pfg6-3wm6 | Third Party Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-01-14T00:34:06.722Z
Updated:
Reserved: 2022-12-29T03:00:40.880Z
Link: CVE-2023-22471
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-01-14T01:15:14.163
Modified: 2023-01-24T18:38:42.310
Link: CVE-2023-22471
JSON object: View
Redhat Information
No data.
CWE