← Back

CVE-2023-28845

nvd nist
Published: Mar 31, 2023Modified: Jun 17, 2026

JSON object

Loading...
3.5
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
Exploitability: 2.1 / Impact: 1.4
Source: NVD

Description

Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members. It is recommended that the Nextcloud Talk is upgraded to 14.0.9 or 15.0.4. There are no known workarounds for this vulnerability.

Affected (2)

Products: Nextcloud: Talk
1 product
Talk
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 14.0.0 to 14.0.9
From 15.0.0 to 15.0.4

References (4)

Source: security-advisories@github.com
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Patch

Timeline

No history available yet.