Vulnerability Description
Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It is recommended that the Nextcloud Talk application is upgraded to 12.2.7, 13.0.7 or 14.0.3. There are currently no known workarounds available apart from not having password protected conversations.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Talk | < 12.2.7 |
Related Weaknesses (CWE)
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pf36-jIssue TrackingThird Party Advisory
- https://github.com/nextcloud/spreed/commit/04300bbed0e87ff3420b5d752bbc48e2c15f3PatchThird Party Advisory
- https://github.com/nextcloud/spreed/commit/10341b9fe59a44ae0d139c072abd6b5026f33PatchRelease NotesThird Party Advisory
- https://github.com/nextcloud/spreed/commit/f5ac73940f9f683b11e518d1c54150bf50dabPatchThird Party Advisory
- https://github.com/nextcloud/spreed/pull/7504Issue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/spreed/pull/7535Issue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/spreed/pull/7536Issue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/spreed/pull/7537Issue TrackingPatchThird Party Advisory
- https://hackerone.com/reports/1596673Issue TrackingThird Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pf36-jIssue TrackingThird Party Advisory
- https://github.com/nextcloud/spreed/commit/04300bbed0e87ff3420b5d752bbc48e2c15f3PatchThird Party Advisory
- https://github.com/nextcloud/spreed/commit/10341b9fe59a44ae0d139c072abd6b5026f33PatchRelease NotesThird Party Advisory
- https://github.com/nextcloud/spreed/commit/f5ac73940f9f683b11e518d1c54150bf50dabPatchThird Party Advisory
- https://github.com/nextcloud/spreed/pull/7504Issue TrackingPatchThird Party Advisory
- https://github.com/nextcloud/spreed/pull/7535Issue TrackingPatchThird Party Advisory
FAQ
What is CVE-2022-35932?
CVE-2022-35932 is a vulnerability with a CVSS score of 3.5 (LOW). Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacke...
How severe is CVE-2022-35932?
CVE-2022-35932 has been rated LOW with a CVSS base score of 3.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-35932?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Talk.