← Back

CVE-2021-22913

nvd nist
Published: Jun 11, 2021Modified: Nov 21, 2024

JSON object

Loading...
6.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Exploitability: 2.8 / Impact: 3.6
Source: NVD

Description

Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only the local Nextcloud server unless a global search has been explicitly chosen by the user.

Affected (2)

Products: Nextcloud: Deck
1 product
Deck
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
Before 1.2.7
From 1.3.0 to 1.4.1

References (4)

Source: support@hackerone.com
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory

Timeline

No history available yet.