CVE-2023-39957Path Traversal in Security-advisories

CWE-22Path Traversal2 documents2 sources
Severity
7.8HIGHNVD
EPSS
0.4%
top 38.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 10

Description

Nextcloud Talk Android allows users to place video and audio calls through Nextcloud on Android. Prior to version 17.0.0, an unprotected intend allowed malicious third party apps to trick the Talk Android app into writing files outside of its intended cache directory. Nextcloud Talk Android version 17.0.0 has a patch for this issue. No known workarounds are available.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

NVDnextcloud/talk< 17.0.0+1
CVEListV5nextcloud/security-advisories< 17.0.0

Patches

🔴Vulnerability Details

1
CVEList
Path traversal allows tricking the Talk Android app into writing files into it's root directory2023-08-10
CVE-2023-39957 — Path Traversal in Security-advisories | cvebase