VYPR
Unrated severityNVD Advisory· Published May 20, 2022· Updated Apr 22, 2025

Error in deleting deck cards attachment reveals the full application path in Nextcloud Deck

CVE-2022-24906

Description

Nextcloud Deck is a Kanban-style project & personal management tool for Nextcloud, similar to Trello. The full path of the application is exposed to unauthorized users. It is recommended that the Nextcloud Deck app is upgraded to 1.2.11, 1.4.6, or 1.5.4. There is no workaround available.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Nextcloud/Deckllm-fuzzy
    Range: <1.2.11, <1.4.6, <1.5.4
  • nextcloud/security-advisoriesv5
    Range: < 1.2.11

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.