CVE-2023-30540

LOW

Nextcloud Talk 15.0.0-15.0.5 - Exposure of Sensitive Information via Deleted Conversation Data

Title source: llm
STIX 2.1

Description

Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that users upgrad to 15.0.5. There are no known workarounds for this issue.

References (3)

Core 3
Core References
Permissions Required x_refsource_misc
https://hackerone.com/reports/1894676

Scores

CVSS v3 3.5
EPSS 0.0029
EPSS Percentile 52.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200
Status published
Products (1)
nextcloud/talk 15.0.0 - 15.0.5
Published Apr 17, 2023
Tracked Since Feb 18, 2026