CVE-2023-28643

CVSS V2 None CVSS V3 None
Description
Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to `{name} (2)`. It is recommended that the Nextcloud Server is upgraded to 25.0.3 or 24.0.9. Users unable to upgrade should avoid sharing 2 folders with the same name to the same user.
Overview
  • CVE ID
  • CVE-2023-28643
  • Assigner
  • security-advisories@github.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-03-30T19:15:06
  • Last Modified Date
  • 2023-04-06T19:03:25
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* 1 OR 24.0.0 24.0.9
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* 1 OR 24.0.0 24.0.9
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* 1 OR 25.0.0 25.0.3
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* 1 OR 25.0.0 25.0.3
History
Created Old Value New Value Data Type Notes
2023-04-17 03:55:35 Added to TrackCVE
2023-04-17 03:55:37 Weakness Enumeration new