Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2022-35932 Details

Description

Nextcloud Talk is a video and audio conferencing app for Nextcloud. Prior to versions 12.2.7, 13.0.7, and 14.0.3, password protected conversations are susceptible to brute force attacks if the attacker has the link/conversation token. It is recommended that the Nextcloud Talk application is upgraded to 12.2.7, 13.0.7 or 14.0.3. There are currently no known workarounds available apart from not having password protected conversations.

Metrics

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pf36-jvpv-4hwq CVEIssue TrackingThird Party Advisory
https://github.com/nextcloud/spreed/commit/04300bbed0e87ff3420b5d752bbc48e2c15f35e9 CVEPatchThird Party Advisory
https://github.com/nextcloud/spreed/commit/10341b9fe59a44ae0d139c072abd6b5026f33771 CVEPatchRelease NotesThird Party Advisory
https://github.com/nextcloud/spreed/commit/f5ac73940f9f683b11e518d1c54150bf50dab9be CVEPatchThird Party Advisory
https://github.com/nextcloud/spreed/pull/7504 CVEIssue TrackingPatchThird Party Advisory

see all 18 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-307Improper Restriction of Excessive Authentication Attempts[email protected]
CWE-359Exposure of Private Personal Information to an Unauthorized Actor[email protected]

Affected Products

ProductVersions
nextcloud talk
< 12.2.7
>= 13.0.0, < 13.0.7
>= 14.0.0, < 14.0.3

CPE

  • cpe:2.3:a:nextcloud:talk:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

5 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2022-35932
NVD Published Date:
Aug 12, 2022
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]