CVE-2022-36075: File list exposure in Nextcloud Files Access Control
Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or 1.14.1. There are no known workarounds for this issue
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-36075?
CVE-2022-36075 has been classified as a moderate severity vulnerability.
How do I fix CVE-2022-36075?
To fix CVE-2022-36075, update the Nextcloud files access control app to version 1.14.0 or higher.
What are the affected versions of CVE-2022-36075?
CVE-2022-36075 affects Nextcloud files access control versions before 1.12.2 and exactly 1.13.0.
Who is affected by CVE-2022-36075?
Users of the Nextcloud files access control app with limited access permissions can be affected by CVE-2022-36075.
What does CVE-2022-36075 affect specifically?
CVE-2022-36075 affects the access control mechanism in Nextcloud files access control, potentially exposing file names to unauthorized users.