SB2023010905 - Improper access control in Nextcloud Android Talk



SB2023010905 - Improper access control in Nextcloud Android Talk

Published: January 9, 2023

Security Bulletin ID SB2023010905
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Physical access
Highest impact Information disclosure

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper access control (CVE-ID: CVE-2023-22473)

The vulnerability allows a local attacker to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions. An attacker with physical access can bypass of passcode and access the user's Nextcloud files and view conversations.


Remediation

Install update from vendor's website.