CVE-2022-36075 LOW

CVE-2022-36075: File list exposure in Nextcloud Files Access Control

Vendor Nextcloud
Product security-advisories
Weakness CWE-200 · Info exposure
Published September 15, 2022
Last update April 23, 2025

CVSS base score

2.6/10
Attack vector Network
Attack complexity High
Privileges required High
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N

What the vulnerability does

01Description

Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or 1.14.1. There are no known workarounds for this issue

Key dates

02Disclosure timeline

September 15, 2022 CVE published
April 23, 2025 Record updated