CVE-2023-28844
Summary
| CVE | CVE-2023-28844 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-03-31 23:15:00 UTC |
| Updated | 2023-04-07 01:43:00 UTC |
| Description | Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versions 24.0.10 and 25.0.4. Users are advised to upgrade. There are no known workarounds for this vulnerability. |
Risk And Classification
Problem Types: CWE-284
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nextcloud | Nextcloud Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Extend ViewOnly DAV plugin to versions endpoint by PVince81 · Pull Request #36113 · nextcloud/server · GitHub | MISC | github.com | |
| User without download rights can download older version of that file · Advisory · nextcloud/security-advisories · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.