Lucene search

K
nvd[email protected]NVD:CVE-2023-48301
HistoryNov 21, 2023 - 10:15 p.m.

CVE-2023-48301

2023-11-2122:15:07
CWE-79
web.nvd.nist.gov
5
nextcloud
server
vulnerability
circle names
fix
workaround

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

20.0%

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, an attacker could insert links into circles name that would be opened when clicking the circle name in a search filter. Nextcloud Server and Nextcloud Enterprise Server versions 25.0.13, 26.0.8, and 27.1.3 contain a fix for this issue. As a workaround, disable app circles.

Affected configurations

Nvd
Node
nextcloudnextcloud_serverRange25.0.025.0.13-
OR
nextcloudnextcloud_serverRange25.0.025.0.13enterprise
OR
nextcloudnextcloud_serverRange26.0.026.0.8-
OR
nextcloudnextcloud_serverRange26.0.026.0.8enterprise
OR
nextcloudnextcloud_serverRange27.0.027.1.3-
OR
nextcloudnextcloud_serverRange27.0.027.1.3enterprise
VendorProductVersionCPE
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
nextcloudnextcloud_server*cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

20.0%