CVE-2021-39225: Missing permission check on Deck API
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9, 1.4.5 or 1.5.3. There are no known workarounds aside from upgrading.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-39225?
CVE-2021-39225 is a vulnerability in Nextcloud Deck that allows authenticated users to access another user's Deck cards.
How does CVE-2021-39225 impact Nextcloud Deck?
CVE-2021-39225 allows authenticated users to access Deck cards of another user.
What is the severity of CVE-2021-39225?
CVE-2021-39225 has a severity rating of 8.1 (high).
How can I fix CVE-2021-39225 in Nextcloud Deck?
To fix CVE-2021-39225, it is recommended to upgrade Nextcloud Deck App to version 1.2.9, 1.4.5, or 1.5.3.
Where can I find more information about CVE-2021-39225?
You can find more information about CVE-2021-39225 in the following references: [Link 1](https://github.com/nextcloud/deck/pull/3316), [Link 2](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2x96-38qg-3m72), [Link 3](https://hackerone.com/reports/1331728).