CVE-2023-22473

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-22473
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-22473.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-22473
Aliases
  • GHSA-wvr4-gc4c-6vmx
Published
2023-01-09T14:07:14Z
Modified
2025-10-23T05:12:24.983252Z
Severity
  • 2.1 (Low) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Passcode bypass on Talk-Android app
Details

Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ]
}
References

Affected packages

Git / github.com/nextcloud/spreed

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/spreed
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*

v1.0.21
v1.0.22
v1.1
v1.1.2
v1.2

v10.*

v10.0.0-beta.1
v10.0.0-beta.2
v10.0.0-rc.1

v11.*

v11.0.0-alpha.1
v11.0.0-alpha.2
v11.0.0-alpha.3
v11.0.0-alpha.4

v12.*

v12.0.0-alpha.1
v12.0.0-alpha.2
v12.0.0-alpha.3

v14.*

v14.0.0-beta.1
v14.0.0-rc.1

v15.*

v15.0.0
v15.0.0-beta.1
v15.0.0-beta.2
v15.0.0-beta.3
v15.0.0-beta.4
v15.0.0-rc.1
v15.0.0-rc.2
v15.0.0-rc.3
v15.0.0-rc.4
v15.0.0-rc.5
v15.0.1

v2.*

v2.0.0
v2.9.0
v2.9.1

v3.*

v3.0.0
v3.0.1
v3.99.10
v3.99.11
v3.99.12
v3.99.8

v4.*

v4.0.0
v4.99.5

v5.*

v5.99.10

v6.*

v6.0.0-rc.1
v6.0.0-rc.2

v7.*

v7.0.0-beta.1

v8.*

v8.0.0
v8.0.0-alpha.1
v8.0.0-alpha.2
v8.0.0-alpha.3
v8.0.0-alpha.4
v8.0.0-alpha.5
v8.0.0-alpha.6

v9.*

v9.0.0-beta.1

Git / github.com/nextcloud/spreed

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/talk-android
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed