CVE-2022-29159Authorization Bypass Through User-Controlled Key in Security-advisories

Severity
4.3MEDIUMNVD
CNA5.0
EPSS
0.2%
top 61.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20

Description

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud. In versions prior to 1.4.8, 1.5.6, and 1.6.1, an authenticated user can move stacks with cards from their own board to a board of another user. The Nextcloud Deck app contains a patch for this issue in versions 1.4.8, 1.5.6, and 1.6.1. There are no known currently-known workarounds available.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDnextcloud/deck1.5.01.5.6+2
CVEListV5nextcloud/security-advisories< 1.4.8+2

Patches

🔴Vulnerability Details

1
CVEList
Possibility for anyone to add a stack with existing tasks on anyone's board in Nextcloud Deck2022-05-20
CVE-2022-29159 — Security-advisories vulnerability | cvebase