CVE-2022-24890: Exposure of Private Personal Information to an Unauthorized Actor in Nextcloud Talk
Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-24890?
CVE-2022-24890 is a vulnerability in Nextcloud Talk that allows a call moderator to indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions.
How can this vulnerability be exploited?
The vulnerability can be exploited by a call moderator who grants permissions to enable user webcams after they have been removed.
Which versions of Nextcloud Talk are affected?
Versions prior to 13.0.5 and 14.0.0-beta1, 14.0.0-rc1, 14.0.0-rc2, 14.0.0-rc3, and 14.0.0-rc4 of Nextcloud Talk are affected.
What is the severity of CVE-2022-24890?
The severity of CVE-2022-24890 is medium with a CVSS score of 4.3.
How can I fix CVE-2022-24890?
To fix CVE-2022-24890, you need to update to Nextcloud Talk version 13.0.5 or 14.0.0.