Описание
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the Nextcloud Deck app is upgraded to 1.6.5 or 1.7.3 or 1.8.2.
Ссылки
- PatchThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.6.5 (исключая)Версия от 1.7.0 (включая) до 1.7.3 (исключая)Версия от 1.8.0 (включая) до 1.8.2 (исключая)
Одно из
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:deck:*:*:*:*:*:*:*:*
EPSS
Процентиль: 29%
0.00106
Низкий
3.5 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-639
CWE-639
EPSS
Процентиль: 29%
0.00106
Низкий
3.5 Low
CVSS3
4.3 Medium
CVSS3
Дефекты
CWE-639
CWE-639