CVE-2023-28644: Reference fetch can saturate the server bandwidth for 10 seconds in nextcloud server
Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-28644?
CVE-2023-28644 is a vulnerability in Nextcloud Server versions before 25.0.3 that can lead to a denial of service and impact server performance due to an inefficient fetch operation.
How severe is CVE-2023-28644?
CVE-2023-28644 has a severity rating of 7.5 (high).
How can I fix CVE-2023-28644?
To fix CVE-2023-28644, it is recommended to upgrade Nextcloud Server to version 25.0.3 or later.
Where can I find more information about CVE-2023-28644?
You can find more information about CVE-2023-28644 in the Nextcloud Security Advisories at https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9wmj-gp8v-477j.
What is the CWE ID for CVE-2023-28644?
The CWE ID for CVE-2023-28644 is 400.