CVE-2023-39952: Advanced permissions not respected when copying entire group folders
Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 22.0.0 and prior to versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1, a user can access files inside a subfolder of a groupfolder accessible to them, even if advanced permissions would block access to the subfolder. Nextcloud Server versions 25.0.8, 26.0.3, and 27.0.1 and Nextcloud Enterprise Server versions 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, and 27.0.1 contain a patch for this issue. No known workarounds are available.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2023-39952.
What is the severity of CVE-2023-39952?
The severity of CVE-2023-39952 is medium with a severity value of 6.5.
How does CVE-2023-39952 affect Nextcloud Server?
CVE-2023-39952 allows a user to access files inside a subfolder of a groupfolder accessible to them, even if advanced permissions are in place.
Which versions of Nextcloud Server are affected by CVE-2023-39952?
The versions affected by CVE-2023-39952 are 22.0.0 to 22.2.10.13, 23.0.0 to 23.0.12.8, 24.0.0 to 24.0.12.4, 25.0.0 to 25.0.8, 26.0.0 to 26.0.3, and 27.0.0.
How can I fix CVE-2023-39952?
To fix CVE-2023-39952, it is recommended to update Nextcloud Server to version 22.2.10.13, 23.0.12.8, 24.0.12.4, 25.0.8, 26.0.3, or 27.0.1.