PT-2023-6441 · Nextcloud+2 · Nextcloud+2

Rullzer

·

Publicado

2023-10-16

·

Atualizado

2025-01-24

·

CVE-2023-45151

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nextcloud versions prior to 25.0.8 Nextcloud versions prior to 26.0.3 Nextcloud versions prior to 27.0.1
Description The issue is related to the storage of OAuth2 tokens in plaintext in Nextcloud, allowing an attacker who has gained access to the server to potentially elevate their privilege.
Recommendations For versions prior to 25.0.8, upgrade to version 25.0.8 or later. For versions prior to 26.0.3, upgrade to version 26.0.3 or later. For versions prior to 27.0.1, upgrade to version 27.0.1 or later.

Exploit

Correção

Cleartext Storage of Sensitive Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2023-7785
ALT-PU-2025-1855
BDU:2023-07158
CVE-2023-45151
GHSA-HHGV-JCG9-P4M9

Produtos afetados

Alt Linux
Nextcloud
Red Os