Information disclosure in Nextcloud Server and Nextcloud Enterprise Server - CVE-2023-28834
Published: April 7, 2023
Vulnerability identifier: #VU74599
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28834
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application. A remote user can obtain the full data directory path of the Nextcloud server from an API endpoint.
Affected software
Nextcloud Server
Nextcloud Enterprise Server
Nextcloud Enterprise Server
How to mitigate CVE-2023-28834
Install updates from vendor's website.
Nextcloud Server - addressed in versions 24.0.10, 25.0.4
Nextcloud Enterprise Server - addressed in versions 23.0.14, 24.0.10, 25.0.4
Nextcloud Enterprise Server - addressed in versions 23.0.14, 24.0.10, 25.0.4