Improper access control in Nextcloud Enterprise Server and Nextcloud Server - CVE-2023-30539
Published: April 21, 2023
Vulnerability identifier: #VU75399
CSH Severity: Medium
CVSS v4: 2.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-30539
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions. A remote user can set up workflows using restricted and invisible system tags.
Affected software
Nextcloud Enterprise Server
Nextcloud Server
Files Automated Tagging App
Nextcloud Server
Files Automated Tagging App
How to mitigate CVE-2023-30539
Install updates from vendor's website.
Nextcloud Enterprise Server - addressed in versions 21.0.9.11, 22.2.10.11, 23.0.12.6, 24.0.11, 25.0.5
Nextcloud Server - addressed in versions 24.0.11, 25.0.5
Files Automated Tagging App - addressed in versions 1.11.1, 1.12.1, 1.13.1, 1.14.2, 1.15.3, 1.16.1
Nextcloud Server - addressed in versions 24.0.11, 25.0.5
Files Automated Tagging App - addressed in versions 1.11.1, 1.12.1, 1.13.1, 1.14.2, 1.15.3, 1.16.1