Skip to content

Session Fixation in Nextcloud Talk

Low
LukasReschke published GHSA-p6h7-84v4-827r Jun 15, 2021

Package

Nextcloud Talk

Affected versions

< 9.0.10, < 10.0.8, < 11.2.2

Patched versions

9.0.10, 10.0.8, 11.2.2

Description

Impact

Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event.

Patches

It is recommended that the Nextcloud Talk App is upgraded to 9.0.10, 10.0.8 or 11.2.2.

Workarounds

None.

References

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2021-32676

Weaknesses

Credits