CVE-2023-25821: Nextcloud download permissions can be changed by resharer
Published Feb 24, 2023
·Updated
Nextcloud is an Open Source private cloud software. Versions 24.0.4 and above, prior to 24.0.7, and 25.0.0 and above, prior to 25.0.1, contain Improper Access Control. Secure view for internal shares can be circumvented if reshare permissions are also given. This issue is patched in versions 24.0.7 and 25.0.1. No workaround is available.
Affected Software
4 affected components
Nextcloud Server>=24.0.4<24.0.7
Nextcloud Server>=24.0.4<24.0.7
Nextcloud Server=25.0.0
Nextcloud Server=25.0.0
Remediation
Patch Available
Event History
Feb 24, 2023
CVE Published
via MITRE·11:39 PM
Data Sourced
via MITRE·11:39 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this Nextcloud vulnerability?
The vulnerability ID for this Nextcloud vulnerability is CVE-2023-25821.
2
What is the severity of CVE-2023-25821?
The severity of CVE-2023-25821 is high.
3
What is the affected software version range for CVE-2023-25821?
The affected software version range for CVE-2023-25821 is versions 24.0.4 to 24.0.7 and versions 25.0.0 to 25.0.1.
4
What is the vulnerability type for CVE-2023-25821?
The vulnerability type for CVE-2023-25821 is Improper Access Control.
5
How can I fix the CVE-2023-25821 vulnerability?
To fix the CVE-2023-25821 vulnerability, update Nextcloud to version 24.0.7 or 25.0.1 or higher.