CVE-2023-28844: User without download rights can download older version of that file in nextcloud server
Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versions 24.0.10 and 25.0.4. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Nextcloud server vulnerability?
The vulnerability ID for this Nextcloud server vulnerability is CVE-2023-28844.
What is the severity of CVE-2023-28844?
The severity of CVE-2023-28844 is medium.
How does CVE-2023-28844 affect Nextcloud server?
In affected versions, users that should not be able to download a file can still download an older version and use that for uncontrolled distribution.
What is the recommended fix for CVE-2023-28844?
The recommended fix for CVE-2023-28844 is to upgrade to versions 24.0.10 or 25.0.4 of Nextcloud server.
Where can I find more information about CVE-2023-28844?
You can find more information about CVE-2023-28844 in the following references: [GitHub Advisory](https://github.com/nextcloud/security-advisories/security/advisories/GHSA-w47p-f66h-h2vj) and [GitHub PR](https://github.com/nextcloud/server/pull/36113).