First published: Sat Jan 14 2023(Updated: )
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the Nextcloud Deck app is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Deck | <1.6.5 | |
Nextcloud Deck | >=1.7.0<1.7.3 | |
Nextcloud Deck | >=1.8.0<1.8.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22471 is a vulnerability in the Nextcloud Deck app that allows a user to delete attachments of other users.
The severity of CVE-2023-22471 is medium with a severity score of 4.3.
CVE-2023-22471 affects Nextcloud Deck versions 1.6.5, 1.7.0 to 1.7.3, and 1.8.0 to 1.8.2.
No, there are currently no known workarounds for CVE-2023-22471.
To fix CVE-2023-22471, it is recommended to upgrade the Nextcloud Deck app to a version that is not affected by the vulnerability.