CVE-2022-39212

Source
https://cve.org/CVERecord?id=CVE-2022-39212
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39212.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-39212
Aliases
  • GHSA-wq3g-2x46-q2gv
Published
2022-09-16T23:15:13Z
Modified
2025-12-04T10:35:27.852173Z
Severity
  • 4.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Last video frame is still sent after video is disabled in a call in Nextcloud Talk
Details

Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected. It is recommended that the Nextcloud Talk app is upgraded to 13.0.8 or 14.0.4. Users unable to upgrade should select "None" as camera before joining the call.

Database specific
{
    "cwe_ids": [
        "CWE-200"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/39xxx/CVE-2022-39212.json"
}
References

Affected packages

Git / github.com/nextcloud/spreed

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/spreed
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "13.0.8"
        }
    ]
}
Type
GIT
Repo
https://github.com/nextcloud/spreed
Events
Database specific
{
    "versions": [
        {
            "introduced": "14.0.0"
        },
        {
            "fixed": "14.0.4"
        }
    ]
}

Affected versions

v1.*
v1.0.21
v1.0.22
v1.1
v1.1.2
v1.2
v10.*
v10.0.0-beta.1
v10.0.0-beta.2
v10.0.0-rc.1
v11.*
v11.0.0-alpha.1
v11.0.0-alpha.2
v11.0.0-alpha.3
v11.0.0-alpha.4
v12.*
v12.0.0-alpha.1
v12.0.0-alpha.2
v12.0.0-alpha.3
v13.*
v13.0.0
v13.0.0-rc.1
v13.0.0-rc.2
v13.0.0-rc.3
v13.0.0-rc.4
v13.0.1
v13.0.1.1
v13.0.2
v13.0.3
v13.0.4
v13.0.5
v13.0.6
v13.0.7
v14.*
v14.0.0
v14.0.1
v14.0.2
v14.0.3
v2.*
v2.0.0
v2.9.0
v2.9.1
v3.*
v3.0.0
v3.0.1
v3.99.10
v3.99.11
v3.99.12
v3.99.8
v4.*
v4.0.0
v4.99.5
v5.*
v5.99.10
v6.*
v6.0.0-rc.1
v6.0.0-rc.2
v7.*
v7.0.0-beta.1
v8.*
v8.0.0
v8.0.0-alpha.1
v8.0.0-alpha.2
v8.0.0-alpha.3
v8.0.0-alpha.4
v8.0.0-alpha.5
v8.0.0-alpha.6
v9.*
v9.0.0-beta.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39212.json"