VYPR
Unrated severityNVD Advisory· Published Apr 17, 2023· Updated Mar 3, 2025

Chat poll data can still be queried from API after purging history in Nextcloud talk

CVE-2023-30540

Description

Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in version 15.0.5 and it is recommended that users upgrad to 15.0.5. There are no known workarounds for this issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Google/Talkllm-fuzzy
    Range: <15.0.5
  • nextcloud/security-advisoriesv5
    Range: >= 15.0.0, < 15.0.5

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.