HIGH
Potential share collision for recipients when caching is enabled in nextcloud server
Published Mar 30, 2023
8.8
HIGHCVSS 3.1
EPSS 0.79%
Description
Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to `{name} (2)`. It is recommended that the Nextcloud Server is upgraded to 25.0.3 or 24.0.9. Users unable to upgrade should avoid sharing 2 folders with the same name to the same user.
Affected products
-
- Version < 24.0.9StatusaffectedConstraints-
- Version >= 25.0.0, < 25.0.3StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Nextcloud | Security-Advisories | n/a |
|
OR
- ≥ 24.0.0 · < 24.0.9
- ≥ 24.0.0 · < 24.0.9
- ≥ 25.0.0 · < 25.0.3
- ≥ 25.0.0 · < 25.0.3
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hhq4-4pr8-wm27 x_refsource_CONFIRMVendor Advisory
- https://github.com/nextcloud/server/issues/34015 x_refsource_MISCExploitIssue Tracking
- https://github.com/nextcloud/server/pull/36047 x_refsource_MISCIssue TrackingPatch
| Link | Providers | Tags |
|---|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hhq4-4pr8-wm27 | x_refsource_CONFIRMVendor Advisory | |
| https://github.com/nextcloud/server/issues/34015 | x_refsource_MISCExploitIssue Tracking | |
| https://github.com/nextcloud/server/pull/36047 | x_refsource_MISCIssue TrackingPatch |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Mar 30, 2023
Updated Feb 11, 2025
Reserved Mar 20, 2023
Link CVE-2023-28643
CISA Vulnrichment
Updated Feb 11, 2025