nextcloud talk 过多认证尝试的限制不恰当

admin 2023-11-30 06:26:31 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
nextcloud talk 过多认证尝试的限制不恰当

CVE编号

CVE-2022-35932

利用情况

暂无

补丁情况

N/A

披露时间

2022-08-13
漏洞描述
Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It is recommended that the Nextcloud Talk application is upgraded to 12.2.7, 13.0.7 or 14.0.3. There are currently no known workarounds available apart from not having password protected conversations.
解决建议
建议您更新当前系统或软件至最新版,完成漏洞的修复。
参考链接
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pf3...
https://github.com/nextcloud/spreed/commit/04300bbed0e87ff3420b5d752bbc48e2c15f35e9
https://github.com/nextcloud/spreed/commit/10341b9fe59a44ae0d139c072abd6b5026f33771
https://github.com/nextcloud/spreed/commit/f5ac73940f9f683b11e518d1c54150bf50dab9be
https://github.com/nextcloud/spreed/pull/7504
https://github.com/nextcloud/spreed/pull/7535
https://github.com/nextcloud/spreed/pull/7536
https://github.com/nextcloud/spreed/pull/7537
https://hackerone.com/reports/1596673
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
应用 nextcloud talk * Up to (excluding) 12.2.7
运行在以下环境
应用 nextcloud talk * From (including) 13.0.0 Up to (excluding) 13.0.7
运行在以下环境
应用 nextcloud talk * From (including) 14.0.0 Up to (excluding) 14.0.3
CVSS3评分 5.3
  • 攻击路径 网络
  • 攻击复杂度 低
  • 权限要求 无
  • 影响范围 未更改
  • 用户交互 无
  • 可用性 无
  • 保密性 低
  • 完整性 无
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CWE-ID 漏洞类型
CWE-307 过多认证尝试的限制不恰当
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0