Vulnerability CVE-2023-22471


Published: 2023-01-14

Description:
Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. Broken access control allows a user to delete attachments of other users. There are currently no known workarounds. It is recommended that the Nextcloud Deck app is upgraded to 1.6.5 or 1.7.3 or 1.8.2.

Type:

CWE-639

(Authorization Bypass Through User-Controlled Key)

 References:
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vw5-pfg6-3wm6
https://github.com/nextcloud/deck/pull/4173

Copyright 2026, cxsecurity.com

 

Back to Top