← Back to CVE List

CVE-2023-28845

Published: 2023-03-31T23:15Z
Last Modified: 2024-11-21T07:56Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Nextcloud talk is a video & audio conferencing app for Nextcloud. In affected versions the talk app does not properly filter access to a conversations member list. As a result an attacker could use this vulnerability to gain information about the members of a Talk conversation, even if they themselves are not members. It is recommended that the Nextcloud Talk is upgraded to 14.0.9 or 15.0.4. There are no known workarounds for this vulnerability. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt