Improper access control in Nextcloud Server and Nextcloud Enterprise Server - CVE-2023-28844
Published: April 7, 2023
Vulnerability identifier: #VU74598
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28844
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user without download permissions can bypass implemented security restrictions and download older versions of files from the server.
Affected software
Nextcloud Server
Nextcloud Enterprise Server
Nextcloud Enterprise Server
How to mitigate CVE-2023-28844
Install updates from vendor's website.
Nextcloud Server - addressed in versions 24.0.10, 25.0.4
Nextcloud Enterprise Server - addressed in versions 24.0.10, 25.0.4
Nextcloud Enterprise Server - addressed in versions 24.0.10, 25.0.4