CVE-2022-29159 — Authorization Bypass Through User-Controlled Key in Security-advisories
Severity
4.3MEDIUMNVD
CNA5.0
EPSS
0.2%
top 61.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 20
Description
Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this issue in versions 1.4.8, 1.5.6, and 1.6.1. There are no known currently-known workarounds available.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4
Affected Packages2 packages
Patches
🔴Vulnerability Details
1CVEList▶
Possibility for anyone to add a stack with existing tasks on anyone's board in Nextcloud Deck↗2022-05-20