Nextcloud Talk is a video and audio conferencing app for Nextcloud. In versions prior to 13.0.5 and 14.0.0, a call moderator can indirectly enable user webcams by granting permissions, if they were enabled before removing the permissions. A patch is available in versions 13.0.5 and 14.0.0. There are currently no known workarounds.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vxpr-hcqq-7fw7 | third party advisory |
https://github.com/nextcloud/spreed/issues/7048 | issue tracking exploit third party advisory |
https://github.com/nextcloud/spreed/pull/7034 | third party advisory exploit |
https://github.com/nextcloud/spreed/pull/7092 | third party advisory patch |