← Back

CVE-2024-37883

nvd nist
Published: Jun 14, 2024Modified: Nov 21, 2024

JSON object

Loading...
4.3
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Exploitability: 2.8 / Impact: 1.4
Source: NVD

Description

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is recommended that the Nextcloud Deck app is upgraded to 1.6.6 or 1.7.5 or 1.8.7 or 1.9.6 or 1.11.3 or 1.12.1.

Affected (11)

Products: Nextcloud: Deck
1 product
Deck
Configuration A
11 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 1.11.0 to 1.11.3
From 1.6.0 to 1.6.6
From 1.7.0 to 1.7.5
From 1.8.0 to 1.8.7
From 1.9.0 to 1.9.6
Version 1.12.0
Version 1.12.0 beta1
Version 1.12.0 beta2
Version 1.12.0 beta3
Version 1.12.0 beta4
Version 1.12.0 beta5

References (6)

Source: security-advisories@github.com
Patch
Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Patch
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking

Timeline

No history available yet.