6.5

CVE-2021-22913

Nextcloud deck sharee search leaks searches to lookupserver by default

Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only the local Nextcloud server unless a global search has been explicitly chosen by the user.
Mögliche Gegenmaßnahme
Nextcloud Deck: None.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudDeck Version < 1.2.7
NextcloudDeck Version >= 1.3.0 < 1.4.1
Weitere Schwachstelleninformationen
SystemNextcloud App
Produkt Nextcloud Deck
Version >= 0.0.0, < 1.2.7
Version >= 1.4.0, < 1.4.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.65% 0.705
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.