{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2025-66553","assignerOrgId":"a0819718-46f1-4df5-94e2-005712e83aaa","state":"PUBLISHED","assignerShortName":"GitHub_M","dateReserved":"2025-12-04T15:57:22.034Z","datePublished":"2025-12-05T17:18:09.776Z","dateUpdated":"2025-12-05T18:44:14.388Z"},"containers":{"cna":{"title":"Nextcloud Tables app allowed users to view columns metadata information of any table","problemTypes":[{"descriptions":[{"cweId":"CWE-639","lang":"en","description":"CWE-639: Authorization Bypass Through User-Controlled Key","type":"CWE"}]}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"NONE","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","version":"3.1"}}],"references":[{"name":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6294-crjw","tags":["x_refsource_CONFIRM"],"url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p53h-6294-crjw"},{"name":"https://github.com/nextcloud/tables/pull/1891","tags":["x_refsource_MISC"],"url":"https://github.com/nextcloud/tables/pull/1891"},{"name":"https://github.com/nextcloud/tables/commit/e975f5bfedb6922f04cdd236cde4e26067fe064e","tags":["x_refsource_MISC"],"url":"https://github.com/nextcloud/tables/commit/e975f5bfedb6922f04cdd236cde4e26067fe064e"},{"name":"https://hackerone.com/reports/3138721","tags":["x_refsource_MISC"],"url":"https://hackerone.com/reports/3138721"}],"affected":[{"vendor":"nextcloud","product":"security-advisories","versions":[{"version":">= 0.9.0-beta.1, < 0.9.4","status":"affected"},{"version":"< 0.8.7","status":"affected"}]}],"providerMetadata":{"orgId":"a0819718-46f1-4df5-94e2-005712e83aaa","shortName":"GitHub_M","dateUpdated":"2025-12-05T17:18:09.776Z"},"descriptions":[{"lang":"en","value":"Nextcloud Tables allows you to create your own tables with individual columns. Prior to 0.8.7 and 0.9.4, authenticated users were able to view meta data of columns in other tables of the Tables app by modifying the numeric ID in a request. This vulnerability is fixed in 0.8.7 and 0.9.4."}],"source":{"advisory":"GHSA-p53h-6294-crjw","discovery":"UNKNOWN"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2025-12-05T18:43:46.446585Z","id":"CVE-2025-66553","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2025-12-05T18:44:14.388Z"}}]}}