Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to 24.0.11 or 25.0.5, the Nextcloud Enterprise Server to 21.0.9.11, 22.2.10.11, 23.0.12.6, 24.0.11 or 25.0.5, and the Nextcloud Files automated tagging app to 1.11.1, 1.12.1, 1.13.1, 1.14.2, 1.15.3 or 1.16.1. Users unable to upgrade should disable all workflow related apps. Users are advised to upgrade.
References
Link | Resource |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-3m2f-v8x7-9w99 | Vendor Advisory |
https://hackerone.com/reports/1895976 | Permissions Required |
https://github.com/nextcloud/server/pull/37252 | Patch |
https://github.com/nextcloud/files_automatedtagging/pull/705 | Issue Tracking Patch |
Configurations
Configuration 1 (hide)
|
History
27 Apr 2023, 16:40
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | (MISC) https://github.com/nextcloud/files_automatedtagging/pull/705 - Issue Tracking, Patch | |
References | (MISC) https://github.com/nextcloud/server/pull/37252 - Patch | |
References | (MISC) https://hackerone.com/reports/1895976 - Permissions Required | |
References | (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-3m2f-v8x7-9w99 - Vendor Advisory | |
CWE | NVD-CWE-noinfo | |
First Time |
Nextcloud nextcloud Server
Nextcloud nextcloud Files Automated Tagging Nextcloud |
|
CPE | cpe:2.3:a:nextcloud:nextcloud_files_automated_tagging:*:*:*:*:*:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* cpe:2.3:a:nextcloud:nextcloud_files_automated_tagging:1.12.0:*:*:*:*:*:*:* cpe:2.3:a:nextcloud:nextcloud_files_automated_tagging:1.16.0:*:*:*:*:*:*:* cpe:2.3:a:nextcloud:nextcloud_files_automated_tagging:1.13.0:*:*:*:*:*:*:* cpe:2.3:a:nextcloud:nextcloud_files_automated_tagging:1.11.0:*:*:*:*:*:*:* |
17 Apr 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-04-17 22:15
Updated : 2023-04-27 16:40
NVD link : CVE-2023-30539
Mitre link : CVE-2023-30539
JSON object : View
Products Affected
nextcloud
- nextcloud_server
- nextcloud_files_automated_tagging
CWE