Low severity3.5NVD Advisory· Published Aug 12, 2022· Updated Jun 17, 2026
CVE-2022-35932
CVE-2022-35932
Description
Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It is recommended that the Nextcloud Talk application is upgraded to 12.2.7, 13.0.7 or 14.0.3. There are currently no known workarounds available apart from not having password protected conversations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: >= 12.2.0, < 12.2.7
Patches
Vulnerability mechanics
References
9- github.com/nextcloud/spreed/commit/04300bbed0e87ff3420b5d752bbc48e2c15f35e9nvdPatchThird Party Advisory
- github.com/nextcloud/spreed/commit/10341b9fe59a44ae0d139c072abd6b5026f33771nvdPatchRelease NotesThird Party Advisory
- github.com/nextcloud/spreed/commit/f5ac73940f9f683b11e518d1c54150bf50dab9benvdPatchThird Party Advisory
- github.com/nextcloud/spreed/pull/7504nvdIssue TrackingPatchThird Party Advisory
- github.com/nextcloud/spreed/pull/7535nvdIssue TrackingPatchThird Party Advisory
- github.com/nextcloud/spreed/pull/7536nvdIssue TrackingPatchThird Party Advisory
- github.com/nextcloud/spreed/pull/7537nvdIssue TrackingPatchThird Party Advisory
- github.com/nextcloud/security-advisories/security/advisories/GHSA-pf36-jvpv-4hwqnvdIssue TrackingThird Party Advisory
- hackerone.com/reports/1596673nvdIssue TrackingThird Party Advisory
News mentions
0No linked articles in our index yet.