Vulnerabilities > CVE-2023-22473 - Unspecified vulnerability in Nextcloud Talk
Attack vector
PHYSICAL Attack complexity
LOW Privileges required
NONE Confidentiality impact
LOW Integrity impact
NONE Availability impact
NONE low complexity
nextcloud
Summary
Talk-Android enables users to have video & audio calls through Nextcloud on Android. Due to passcode bypass, an attacker is able to access the user's Nextcloud files and view conversations. To exploit this the attacker needs to have physical access to the target's device. There are currently no known workarounds available. It is recommended that the Nextcloud Talk Android app is upgraded to 15.0.2.
Vulnerable Configurations
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wvr4-gc4c-6vmx
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wvr4-gc4c-6vmx
- https://github.com/nextcloud/talk-android/pull/2598
- https://github.com/nextcloud/talk-android/pull/2598
- https://hackerone.com/reports/1784645
- https://hackerone.com/reports/1784645