Product:

Deck

(Nextcloud)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 15
Date Id Summary Products Score Patch Annotated
2020-07-02 CVE-2020-8179 Improper access control in Nextcloud Deck 1.0.0 allowed an attacker to inject tasks into other users decks. Deck 4.1
2020-10-05 CVE-2020-8182 Improper access control in Nextcloud Deck 0.8.0 allowed an attacker to reshare boards shared with them with more permissions than they had themselves. Deck 8.0
2020-10-05 CVE-2020-8235 Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments. Deck 4.3
2021-02-23 CVE-2020-8297 Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user. Deck 4.3
2021-06-11 CVE-2021-22913 Nextcloud Deck before 1.2.7, 1.4.1 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only the local Nextcloud server unless a global search has been explicitly chosen by the user. Deck 6.5