Lucene search

K
nvd[email protected]NVD:CVE-2023-26482
HistoryMar 30, 2023 - 7:15 p.m.

CVE-2023-26482

2023-03-3019:15:06
CWE-78
web.nvd.nist.gov
5
nextcloud
scope validation
non-admin
rce
upgrade
mitigation

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.002

Percentile

52.4%

Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only available for administrators. Some workflows are designed to be RCE by invoking defined scripts, in order to generate PDFs, invoking webhooks or running scripts on the server. Due to this combination depending on the available apps the issue can result in a RCE at the end. It is recommended that the Nextcloud Server is upgraded to 24.0.10 or 25.0.4. Users unable to upgrade should disable app workflow_scripts and workflow_pdf_converter as a mitigation.

Affected configurations

Nvd
Node
nextcloudnextcloud_serverRange18.0.020.0.14.12enterprise
OR
nextcloudnextcloud_serverRange21.0.021.0.9.10enterprise
OR
nextcloudnextcloud_serverRange22.0.022.2.10.10enterprise
OR
nextcloudnextcloud_serverRange23.0.023.0.12.5enterprise
OR
nextcloudnextcloud_serverRange24.0.024.0.10-
OR
nextcloudnextcloud_serverRange24.0.024.0.10enterprise
OR
nextcloudnextcloud_serverRange25.0.025.0.4-
OR
nextcloudnextcloud_serverRange25.0.025.0.4enterprise
VendorProductVersionCPE
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

9

Confidence

High

EPSS

0.002

Percentile

52.4%