CVE-2024-37883
CVSS V2 None
CVSS V3 None
Description
Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is recommended that the Nextcloud Deck app is upgraded to 1.6.6 or 1.7.5 or 1.8.7 or 1.9.6 or 1.11.3 or 1.12.1.
Overview
- CVE ID
- CVE-2024-37883
- Assigner
- GitHub_M
- Vulnerability Status
- PUBLISHED
- Published Version
- 2024-06-14T15:33:18.525Z
- Last Modified Date
- 2024-06-17T14:44:36.528Z
Weakness Enumerations
References
Reference URL | Reference Tags |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x45g-vx69-r9m8 | x_refsource_CONFIRM |
https://github.com/nextcloud/deck/pull/5423 | x_refsource_MISC |
https://hackerone.com/reports/2289333 | x_refsource_MISC |
Sources
Source Name | Source URL |
---|---|
NIST | https://nvd.nist.gov/vuln/detail/CVE-2024-37883 |
MITRE | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-37883 |
History
Created | Old Value | New Value | Data Type | Notes |
---|---|---|---|---|
2024-06-26 01:18:48 | Added to TrackCVE |