CVE-2024-37883

June 14, 2024, 4:15 p.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Nextcloud Deck

  • 1.6.6
  • 1.7.5
  • 1.8.7
  • 1.9.6
  • 1.11.3
  • 1.12.1

Source

security-advisories@github.com

Tags

CVE-2024-37883 details

Published : June 14, 2024, 4:15 p.m.
Last Modified : June 14, 2024, 4:15 p.m.

Description

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is recommended that the Nextcloud Deck app is upgraded to 1.6.6 or 1.7.5 or 1.8.7 or 1.9.6 or 1.11.3 or 1.12.1.

CVSS Score

1 2 3 4.3 5 6 7 8 9 10

Weakness

Weakness Name Description

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

Base Score

4.3

Exploitability Score

Impact Score

Base Severity

MEDIUM

References

URL Source
https://github.com/nextcloud/deck/pull/5423 security-advisories@github.com
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x45g-vx69-r9m8 security-advisories@github.com
https://hackerone.com/reports/2289333 security-advisories@github.com
This website uses the NVD API, but is not approved or certified by it.