Описание
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.
Ссылки
- Third Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
- Third Party Advisory
- PatchThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 15.0.2 (исключая)
cpe:2.3:a:nextcloud:talk:*:*:*:*:*:android:*:*
EPSS
Процентиль: 25%
0.00087
Низкий
2.1 Low
CVSS3
Дефекты
CWE-284
EPSS
Процентиль: 25%
0.00087
Низкий
2.1 Low
CVSS3
Дефекты
CWE-284