8.8
CVE-2023-28643
- EPSS 0.66%
- Veröffentlicht 30.03.2023 19:15:06
- Zuletzt bearbeitet 21.11.2024 07:55:43
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Potential share collision for recipients when caching is enabled in nextcloud server
Potential share collision for recipients when caching is enabled
Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to `{name} (2)`. It is recommended that the Nextcloud Server is upgraded to 25.0.3 or 24.0.9. Users unable to upgrade should avoid sharing 2 folders with the same name to the same user.Mögliche Gegenmaßnahme
Server: Avoid sharing 2 folders with the same name to the same user.
Enterprise Server: Avoid sharing 2 folders with the same name to the same user.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Nextcloud Server SwEdition- Version >= 24.0.0 < 24.0.9
Nextcloud ≫ Nextcloud Server SwEditionenterprise Version >= 24.0.0 < 24.0.9
Nextcloud ≫ Nextcloud Server SwEdition- Version >= 25.0.0 < 25.0.3
Nextcloud ≫ Nextcloud Server SwEditionenterprise Version >= 25.0.0 < 25.0.3
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemNextcloud
≫
Produkt
Server
Version
>= 24.0.0, < 24.0.9
Version
>= 25.0.0, < 25.0.3
SystemNextcloud
≫
Produkt
Enterprise Server
Version
>= 24.0.0, < 24.0.9
Version
>= 25.0.0, < 25.0.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.66% | 0.711 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| security-advisories@github.com | 5.5 | 2.1 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L
|
CWE-706 Use of Incorrectly-Resolved Name or Reference
The product uses a name or reference to access a resource, but the name/reference resolves to a resource that is outside of the intended control sphere.