CVE-2023-30540

Source
https://cve.org/CVERecord?id=CVE-2023-30540
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30540.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2023-30540
Aliases
  • GHSA-c9hr-cq65-9mjw
Published
2023-04-17T21:32:29.470Z
Modified
2026-04-02T08:54:15.953238Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Chat poll data can still be queried from API after purging history in Nextcloud talk
Details

Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that users upgrad to 15.0.5. There are no known workarounds for this issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/30xxx/CVE-2023-30540.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-200"
    ]
}
References

Affected packages

Git / github.com/nextcloud/spreed

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/spreed
Events

Affected versions

v15.*
v15.0.0
v15.0.1
v15.0.2
v15.0.3
v15.0.4

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-30540.json"