Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Aslfvo

#33866de 53,639
7.8CVSS total
Vulnerabilidades · 1
PT-2023-2471
7.8
2023-01-23
Nextcloud · Nextcloud Server · CVE-2023-28643
**Name of the Vulnerable Software and Affected Versions** Nextcloud Server versions prior to 24.0.9 Nextcloud Server versions prior to 25.0.3 **Description** The issue is related to the handling of shared resources with the same name in Nextcloud Server, particularly when a memory cache is configured. If a recipient receives two shares with the same name, the second share will replace the first one instead of being renamed to `{name} (2)`. This can lead to a denial of service. The vulnerability can be exploited by a remote attacker to cause a collision of shared resources for recipients when caching is enabled. **Recommendations** For Nextcloud Server versions prior to 24.0.9, upgrade to version 24.0.9. For Nextcloud Server versions prior to 25.0.3, upgrade to version 25.0.3. As a temporary workaround for users unable to upgrade, avoid sharing two folders with the same name to the same user.