MEDIUM
Error in deleting deck cards attachment reveals the full application path in Nextcloud Deck
Published May 20, 2022
4.3
MEDIUMCVSS 3.1
EPSS 1.06%
Description
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.
Affected products
-
- Version < 1.2.11StatusaffectedConstraints-
- Version >= 1.4.0, < 1.4.6StatusaffectedConstraints-
- Version >= 1.5.0, < 1.5.4StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Nextcloud | Security-Advisories | n/a |
|
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (4)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-29663 Advisory
- https://github.com/nextcloud/deck/pull/3384 x_refsource_MISCIssue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hx9w-xfrg-2qvp x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory
- https://hackerone.com/reports/1354334 x_refsource_MISCExploitIssue TrackingThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-29663 | Advisory | |
| https://github.com/nextcloud/deck/pull/3384 | x_refsource_MISCIssue TrackingPatchThird Party Advisory | |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hx9w-xfrg-2qvp | x_refsource_CONFIRMExploitIssue TrackingThird Party Advisory | |
| https://hackerone.com/reports/1354334 | x_refsource_MISCExploitIssue TrackingThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published May 20, 2022
Updated Apr 22, 2025
Reserved Feb 10, 2022
Link CVE-2022-24906
CISA Vulnrichment
Updated Apr 22, 2025
ENISA EUVD
EUVD-2022-29663 Assigner GitHub_M
Published May 20, 2022
Updated Apr 22, 2025
Exploited since n/a
Link EUVD-2022-29663