First published: Fri May 20 2022(Updated: )
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.6 and 23.0.3, a user can create a link that is not password protected even if the administrator requires links to be password protected. Versions 22.2.6 and 23.0.3 contain a patch for this issue. There are currently no known workarounds.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | <22.2.6 | |
Nextcloud Nextcloud Server | >=23.0.0<23.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for Nextcloud Server is CVE-2022-29163.
The severity of CVE-2022-29163 is medium (4.3).
The affected software is Nextcloud Server versions up to 22.2.6 and versions up to 23.0.3.
To create a password-protected link, the administrator of Nextcloud Server should enable the option to require password protection for links.
You can find more information about CVE-2022-29163 in the references: [Link 1](https://github.com/nextcloud/circles/pull/866), [Link 2](https://github.com/nextcloud/circles/pull/926), [Link 3](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pwjv-h37v-c4fx).