PT-2023-2377 · Nextcloud+2 · Nextcloud+2

Rullzer

·

Published

2023-01-16

·

Updated

2023-04-13

·

CVE-2023-25821

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud versions 24.0.4 through 24.0.6 Nextcloud versions 25.0.0
Description The issue is related to improper access control in Nextcloud, a private cloud software. This can allow a remote attacker to gain unauthorized access to limited functions. Specifically, the secure view for internal shares can be circumvented if reshare permissions are also given.
Recommendations For Nextcloud versions 24.0.4 through 24.0.6, update to version 24.0.7 to resolve the issue. For Nextcloud versions 25.0.0, update to version 25.0.1 to resolve the issue.

Exploit

Fix

Improper Access Control

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1055
ALT-PU-2023-1176
BDU:2023-02152
BDU:2023-02153
CVE-2023-25821
GHSA-7W6H-5QGW-4J94

Affected Products

Alt Linux
Nextcloud
Red Os