Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
Link | Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hx9w-xfrg-2qvp | issue tracking exploit third party advisory |
https://github.com/nextcloud/deck/pull/3384 | issue tracking third party advisory patch |
https://hackerone.com/reports/1354334 | issue tracking exploit third party advisory |