CVE-2023-39961

Severity
4.3MEDIUM
EPSS
0.3%
top 51.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 10

Description

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 24.0.4 and prior to versions 25.0.9, 26.0.4, and 27.0.1, when a folder with images or an image was shared without download permissions, the user could add the image inline into a text file and download it. Nextcloud Server versions 25.0.9, 26.0.4, and 27.0.1 and Nextcloud Enterprise Server versions 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1 contain a patch for this issue. No known workarounds are

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:NExploitability: 2.1 | Impact: 1.4

Affected Packages2 packages

NVDnextcloud/nextcloud_server25.0.025.0.9+2
CVEListV5nextcloud/security-advisories4 versions+3

Patches

🔴Vulnerability Details

1
CVEList
Text does not respect "Allow download" permissions2023-08-10
CVE-2023-39961 (MEDIUM CVSS 4.3) | Nextcloud Server provides data stor | cvebase.io