CVE-2023-22473

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2023-22473
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22473.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-22473
Aliases
  • GHSA-wvr4-gc4c-6vmx
Published
2023-01-09T15:15:11Z
Modified
2024-09-03T04:13:51.727967Z
Severity
  • 2.1 (Low) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.

References

Affected packages

Git / github.com/nextcloud/spreed

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/spreed
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/nextcloud/talk-android
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*

v1.0.21
v1.0.22
v1.1
v1.1.2
v1.2

v10.*

v10.0.0-beta.1
v10.0.0-beta.2
v10.0.0-rc.1

v11.*

v11.0.0-alpha.1
v11.0.0-alpha.2
v11.0.0-alpha.3
v11.0.0-alpha.4

v12.*

v12.0.0-alpha.1
v12.0.0-alpha.2
v12.0.0-alpha.3

v14.*

v14.0.0-beta.1
v14.0.0-rc.1

v15.*

v15.0.0
v15.0.0-beta.1
v15.0.0-beta.2
v15.0.0-beta.3
v15.0.0-beta.4
v15.0.0-rc.1
v15.0.0-rc.2
v15.0.0-rc.3
v15.0.0-rc.4
v15.0.0-rc.5
v15.0.1

v2.*

v2.0.0
v2.9.0
v2.9.1

v3.*

v3.0.0
v3.0.1
v3.99.10
v3.99.11
v3.99.12
v3.99.8

v4.*

v4.0.0
v4.99.5

v5.*

v5.99.10

v6.*

v6.0.0-rc.1
v6.0.0-rc.2

v7.*

v7.0.0-beta.1

v8.*

v8.0.0
v8.0.0-alpha.1
v8.0.0-alpha.2
v8.0.0-alpha.3
v8.0.0-alpha.4
v8.0.0-alpha.5
v8.0.0-alpha.6

v9.*

v9.0.0-beta.1