Lucene search

K
cveGitHub_MCVE-2023-28643
HistoryMar 30, 2023 - 7:15 p.m.

CVE-2023-28643

2023-03-3019:15:06
CWE-706
GitHub_M
web.nvd.nist.gov
32
nextcloud
cve-2023-28643
vulnerability
share replacement
memory cache
upgrade
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

43.6%

Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to {name} (2). It is recommended that the Nextcloud Server is upgraded to 25.0.3 or 24.0.9. Users unable to upgrade should avoid sharing 2 folders with the same name to the same user.

Affected configurations

Nvd
Vulners
Node
nextcloudnextcloud_serverRange24.0.024.0.9-
OR
nextcloudnextcloud_serverRange24.0.024.0.9enterprise
OR
nextcloudnextcloud_serverRange25.0.025.0.3-
OR
nextcloudnextcloud_serverRange25.0.025.0.3enterprise
VendorProductVersionCPE
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

CNA Affected

[
  {
    "vendor": "nextcloud",
    "product": "security-advisories",
    "versions": [
      {
        "version": "< 24.0.9",
        "status": "affected"
      },
      {
        "version": ">= 25.0.0, < 25.0.3",
        "status": "affected"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

43.6%