CVE-2022-36075

Source
https://cve.org/CVERecord?id=CVE-2022-36075
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36075.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-36075
Aliases
  • GHSA-4m73-g7v7-v62w
Published
2022-09-15T21:50:10Z
Modified
2026-02-22T02:47:15.689763Z
Severity
  • 2.6 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N CVSS Calculator
Summary
File list exposure in Nextcloud Files Access Control
Details

Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or 1.14.1. There are no known workarounds for this issue

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/36xxx/CVE-2022-36075.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/nextcloud/files_accesscontrol

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/files_accesscontrol
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.12.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/nextcloud/files_accesscontrol
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.13.0"
        },
        {
            "fixed": "1.13.1"
        }
    ]
}
Type
GIT
Repo
https://github.com/nextcloud/files_accesscontrol
Events
Database specific
{
    "versions": [
        {
            "introduced": "1.14.0"
        },
        {
            "fixed": "1.14.1"
        }
    ]
}

Affected versions

v1.*
v1.11.0
v1.12.0
v1.12.1
v1.13.0
v1.14.0
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.3.0
v1.4.0
v1.6.0
v1.8.0
v1.8.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-36075.json"