CVE-2023-28845

Source
https://cve.org/CVERecord?id=CVE-2023-28845
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28845.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-28845
Aliases
  • GHSA-3m6r-479j-4chf
Published
2023-03-31T22:13:44.046Z
Modified
2026-04-02T08:49:12.299749Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Chat room membership disclosed via autocompletion in Nextcloud talk
Details

Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members. It is recommended that the Nextcloud Talk is upgraded to 14.0.9 or 15.0.4. There are no known workarounds for this vulnerability.

Database specific
{
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/28xxx/CVE-2023-28845.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/spreed

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/spreed
Events
Database specific
{
    "versions": [
        {
            "introduced": "15.0.0"
        },
        {
            "fixed": "15.0.4"
        }
    ]
}
Type
GIT
Repo
https://github.com/nextcloud/spreed
Events
Database specific
{
    "versions": [
        {
            "introduced": "14.0.0"
        },
        {
            "fixed": "14.0.9"
        }
    ]
}

Affected versions

v14.*
v14.0.0
v14.0.1
v14.0.2
v14.0.3
v14.0.4
v14.0.5
v14.0.6
v14.0.7
v14.0.8
v15.*
v15.0.0
v15.0.1
v15.0.2
v15.0.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-28845.json"