CVE-2023-30539
Summary
| CVE | CVE-2023-30539 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-04-17 22:15:00 UTC |
| Updated | 2023-04-27 16:40:00 UTC |
| Description | Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to 24.0.11 or 25.0.5, the Nextcloud Enterprise Server to 21.0.9.11, 22.2.10.11, 23.0.12.6, 24.0.11 or 25.0.5, and the Nextcloud Files automated tagging app to 1.11.1, 1.12.1, 1.13.1, 1.14.2, 1.15.3 or 1.16.1. Users unable to upgrade should disable all workflow related apps. Users are advised to upgrade. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nextcloud | Nextcloud Files Automated Tagging | All | All | All | All |
| Application | Nextcloud | Nextcloud Files Automated Tagging | 1.11.0 | All | All | All |
| Application | Nextcloud | Nextcloud Files Automated Tagging | 1.12.0 | All | All | All |
| Application | Nextcloud | Nextcloud Files Automated Tagging | 1.13.0 | All | All | All |
| Application | Nextcloud | Nextcloud Files Automated Tagging | 1.16.0 | All | All | All |
| Application | Nextcloud | Nextcloud Server | All | All | All | All |
| Application | Nextcloud | Nextcloud Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| fix(workflow): Check tag attributes by nickvergessen · Pull Request #37252 · nextcloud/server · GitHub | MISC | github.com | |
| Users can set up workflows using restricted and invisible system tags · Advisory · nextcloud/security-advisories · GitHub | MISC | github.com | |
| HackerOne | MISC | hackerone.com | |
| fix: Check tag attribute by nickvergessen · Pull Request #705 · nextcloud/files_automatedtagging · GitHub | MISC | github.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.