Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members. It is recommended that the Nextcloud Talk is upgraded to 14.0.9 or 15.0.4. There are no known workarounds for this vulnerability.
History

Tue, 11 Feb 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-02-11T17:13:26.478Z

Reserved: 2023-03-24T16:25:34.466Z

Link: CVE-2023-28845

cve-icon Vulnrichment

Updated: 2024-08-02T13:51:38.693Z

cve-icon NVD

Status : Modified

Published: 2023-03-31T23:15:07.533

Modified: 2024-11-21T07:56:08.690

Link: CVE-2023-28845

cve-icon Redhat

No data.