CVE-2023-25159
Nextcloud Server previews are accessible without a watermark
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Office is a document collaboration app for the same platform. Nextcloud Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, Nextcloud Enterprise Server 24.0.x prior to 24.0.8 and 25.0.x prior to 25.0.1, and Nextcloud Office (Richdocuments) App 6.x prior to 6.3.1 and 7.x prior to 7.0.1 have previews accessible without a watermark. The download should be hidden and the watermark should get applied. This issue is fixed in Nextcloud Server 25.0.1 and 24.0.8, Nextcloud Enterprise Server 25.0.1 and 24.0.8, and Nextcloud Office (Richdocuments) App 7.0.1 (for 25) and 6.3.1 (for 24). No known workarounds are available.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-02-03 CVE Reserved
- 2023-02-13 CVE Published
- 2024-08-02 CVE Updated
- 2024-09-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/richdocuments/pull/2579 | Broken Link | |
https://github.com/nextcloud/server/pull/34799 | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-92g2-h5jv-jjmg | 2023-11-07 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 24.0.4 <= 24.0.8 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 24.0.4 <= 24.0.8" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | 24.0.2 Search vendor "Nextcloud" for product "Nextcloud Server" and version "24.0.2" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | 25.0.0 Search vendor "Nextcloud" for product "Nextcloud Server" and version "25.0.0" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Richdocuments Search vendor "Nextcloud" for product "Richdocuments" | >= 6.0.0 < 6.3.1 Search vendor "Nextcloud" for product "Richdocuments" and version " >= 6.0.0 < 6.3.1" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Richdocuments Search vendor "Nextcloud" for product "Richdocuments" | 7.0.0 Search vendor "Nextcloud" for product "Richdocuments" and version "7.0.0" | - |
Affected
|