CVE-2022-24890
Dashboard / Vulnerabilities / CVE-2022-24890
Summary: Exposure of Private Personal Information to an Unauthorized Actor in Nextcloud Talk
Details: Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.
References: https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/24xxx/CVE-2022-24890.json, https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vxpr-hcqq-7fw7, https://nvd.nist.gov/vuln/detail/CVE-2022-24890, https://github.com/nextcloud/spreed/issues/7048, https://github.com/nextcloud/spreed/pull/7034, https://github.com/nextcloud/spreed/pull/7092
Affected packages
Package
Name:
Purl:
