Back

MEDIUM

Secure view can be bypassed by using internal API endpoint in Nextcloud richdocuments

Published Mar 31, 2023

Description

Nextcloud richdocuments is a Nextcloud app integrating the office suit Collabora Online. In affected versions the secure view feature of the rich documents app can be bypassed by using unprotected internal API endpoint of the rich documents app. It is recommended that the Nextcloud Office app (richdocuments) is upgraded to 8.0.0-beta.1, 7.0.2 or 6.3.2. Users unable to upgrade may mitigate the issue by taking steps to restrict the ability to download documents. This includes ensuring that the `WOPI configuration` is configured to only serve documents between Nextcloud and Collabora. It is highly recommended to define the list of Collabora server IPs as the allow list within the Office admin settings of Nextcloud.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner GitHub_M
Published Mar 31, 2023
Updated Feb 11, 2025
Reserved Mar 20, 2023

CISA Vulnrichment

Updated Feb 11, 2025

NVD

Status Modified
Modified Jun 17, 2026

Red Hat

No data

ENISA EUVD

Assigner GitHub_M
Published Mar 31, 2023
Updated Feb 11, 2025

GitHub

No data