CVE-2022-39212

MEDIUM

Nextcloud Talk < 13.0.8 - Unauthorized Exposure of Last Video Frame

Title source: llm
STIX 2.1

Description

Nextcloud Talk is an open source chat, video & audio calls client for the Nextcloud platform. In affected versions an attacker could see the last video frame of any participant who has video disabled but a camera selected. It is recommended that the Nextcloud Talk app is upgraded to 13.0.8 or 14.0.4. Users unable to upgrade should select "None" as camera before joining the call.

References (2)

Core 2
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/nextcloud/spreed/pull/7673

Scores

CVSS v3 4.3
EPSS 0.0024
EPSS Percentile 46.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
nextcloud/talk < 13.0.8
Published Sep 17, 2022
Tracked Since Feb 18, 2026