First published: Mon Jan 09 2023(Updated: )
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. It is possible to make a user send any POST request with an arbitrary body given they click on a malicious deep link on a Windows computer. (e.g. in an email, chat link, etc). There are currently no known workarounds. It is recommended that the Nextcloud Desktop client is upgraded to 3.6.2.
Credit: security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Desktop | =3.6.1 | |
=3.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22472 is a vulnerability in the Deck kanban style organization tool integrated with Nextcloud, which allows a user to send any POST request with an arbitrary body by clicking on a malicious deep link on a Windows computer.
CVE-2023-22472 affects Nextcloud Desktop version 3.6.1 and allows a user to send unauthorized POST requests through malicious deep links.
The severity of CVE-2023-22472 is high, with a CVSS score of 8.8.
To fix CVE-2023-22472, update Nextcloud Desktop to a version that includes the security patch.
You can find more information about CVE-2023-22472 in the Nextcloud Desktop security advisories and the related GitHub pull request.