CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
43.6%
Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to {name} (2)
. It is recommended that the Nextcloud Server is upgraded to 25.0.3 or 24.0.9. Users unable to upgrade should avoid sharing 2 folders with the same name to the same user.
Vendor | Product | Version | CPE |
---|---|---|---|
nextcloud | nextcloud_server | * | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* |
nextcloud | nextcloud_server | * | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* |
[
{
"vendor": "nextcloud",
"product": "security-advisories",
"versions": [
{
"version": "< 24.0.9",
"status": "affected"
},
{
"version": ">= 25.0.0, < 25.0.3",
"status": "affected"
}
]
}
]