CVE-2022-39212
Last video frame is still sent after video is disabled in a call in Nextcloud Talk
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected. It is recommended that the Nextcloud Talk app is upgraded to 13.0.8 or 14.0.4. Users unable to upgrade should select "None" as camera before joining the call.
Nextcloud Talk es un cliente de código abierto de chat, vídeo y llamadas de audio para la plataforma Nextcloud. En versiones afectadas, un atacante podría visualizar el último fotograma de vídeo de cualquier participante que tenga el vídeo deshabilitado pero una cámara seleccionada. Es recomendado actualizar la aplicación Nextcloud Talk a versión 13.0.8 o 14.0.4. Los usuarios que no puedan actualizar deberán seleccionar "None" como cámara antes de unirse a la llamada
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-02 CVE Reserved
- 2022-09-16 CVE Published
- 2024-04-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wq3g-2x46-q2gv | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/spreed/pull/7673 | 2022-09-21 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Talk Search vendor "Nextcloud" for product "Talk" | < 13.0.8 Search vendor "Nextcloud" for product "Talk" and version " < 13.0.8" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Talk Search vendor "Nextcloud" for product "Talk" | >= 14.0.0 < 14.0.4 Search vendor "Nextcloud" for product "Talk" and version " >= 14.0.0 < 14.0.4" | - |
Affected
|