TROYANOSYVIRUS
Voltar para CVEs

CVE-2021-37631

MEDIUM
6.5

Descricao

Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions the Deck application didn't properly check membership of users in a Circle. This allowed other users in the instance to gain access to boards that have been shared with a Circle, even if the user was not a member of the circle. It is recommended that Nextcloud Deck is upgraded to 1.5.1, 1.4.4 or 1.2.9. If you are unable to update it is advised to disable the Deck plugin.

Detalhes CVE

Pontuacao CVSS v3.16.5
SeveridadeMEDIUM
Vetor CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Vetor de ataqueNETWORK
ComplexidadeLOW
Privilegios necessariosLOW
Interacao do usuarioNONE
Publicado9/7/2021
Ultima modificacao11/21/2024
Fontenvd
Avistamentos honeypot0

Produtos afetados

nextcloud:deck

Fraquezas (CWE)

CWE-639CWE-639

Referencias

https://github.com/nextcloud/deck/pull/3217(security-advisories@github.com)
https://hackerone.com/reports/1256021(security-advisories@github.com)
https://hackerone.com/reports/1280931(security-advisories@github.com)
https://github.com/nextcloud/deck/pull/3217(af854a3a-2127-422b-91ae-364da2661108)
https://hackerone.com/reports/1256021(af854a3a-2127-422b-91ae-364da2661108)
https://hackerone.com/reports/1280931(af854a3a-2127-422b-91ae-364da2661108)

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.