cbcvebase.
CVE-2023-35928
published 2023-06-23

CVE-2023-35928: Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0…

PriorityP352high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.98%
57.8th percentile
Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 19.0.0 until 19.0.13.9, 20.0.0 until 20.0.14.14, 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0 until 24.0.12.2, 25.0.0 until 25.0.7, and 26.0.0 until 26.0.2, a user could use this functionality to get access to the login credentials of another user and take over their account. This issue has been patched in Nextcloud Server versions 25.0.7 and 26.0.2 and NextCloud Enterprise Server versions 19.0.13.9, 20.0.14.14, 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, and 26.0.2. Three workarounds are available. Disable app files_external. Change config setting "Allow users to mount external storage" to disabled in "Administration" > "External storage" settings `…/index.php/settings/admin/externalstorages`. Change config setting to disallow users to create external storages in "Administration" > "External storage" settings `…/index.php/settings/admin/externalstorages` with the types FTP, Nextcloud, SFTP, and/or WebDAV.

Affected

18 ranges
VendorProductVersion rangeFixed in
nextcloudnextcloud_server>= 19.0.0 < 19.0.13.919.0.13.9
nextcloudnextcloud_server>= 20.0.0 < 20.0.14.1420.0.14.14
nextcloudnextcloud_server>= 21.0.0 < 21.0.9.1221.0.9.12
nextcloudnextcloud_server>= 22.0.0 < 22.2.10.1222.2.10.12
nextcloudnextcloud_server>= 23.0.0 < 23.0.12.723.0.12.7
nextcloudnextcloud_server>= 24.0.0 < 24.0.12.224.0.12.2
nextcloudnextcloud_server>= 25.0.0 < 25.0.725.0.7
nextcloudnextcloud_server>= 26.0.0 < 26.0.226.0.2
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudsecurity-advisories
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.