CVE-2022-31024

richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and 4.2.6 contain a fix for this issue. There are currently no known workarounds available.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:richdocuments:6.0.0:beta1:*:*:*:*:*:*

History

No history.

Information

Published : 2022-06-02 19:15

Updated : 2022-06-13 16:20


NVD link : CVE-2022-31024

Mitre link : CVE-2022-31024

CVE.ORG link : CVE-2022-31024


JSON object : View

Products Affected

nextcloud

  • richdocuments
CWE
CWE-284

Improper Access Control

CWE-346

Origin Validation Error