First published: Mon Oct 25 2021(Updated: )
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9, 1.4.5 or 1.5.3. There are no known workarounds aside from upgrading.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Deck | <1.2.9 | |
Nextcloud Deck | >=1.3.0<1.4.5 | |
Nextcloud Deck | >=1.5.0<1.5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-39225 is a vulnerability in Nextcloud Deck that allows authenticated users to access another user's Deck cards.
CVE-2021-39225 allows authenticated users to access Deck cards of another user.
CVE-2021-39225 has a severity rating of 8.1 (high).
To fix CVE-2021-39225, it is recommended to upgrade Nextcloud Deck App to version 1.2.9, 1.4.5, or 1.5.3.
You can find more information about CVE-2021-39225 in the following references: [Link 1](https://github.com/nextcloud/deck/pull/3316), [Link 2](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2x96-38qg-3m72), [Link 3](https://hackerone.com/reports/1331728).