CVE-2023-30539
Users can set up workflows using restricted and invisible system tags in Nextcloud
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to 24.0.11 or 25.0.5, the Nextcloud Enterprise Server to 21.0.9.11, 22.2.10.11, 23.0.12.6, 24.0.11 or 25.0.5, and the Nextcloud Files automated tagging app to 1.11.1, 1.12.1, 1.13.1, 1.14.2, 1.15.3 or 1.16.1. Users unable to upgrade should disable all workflow related apps. Users are advised to upgrade.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-04-12 CVE Reserved
- 2023-04-17 CVE Published
- 2024-08-02 CVE Updated
- 2024-11-22 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-284: Improper Access Control
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/files_automatedtagging/pull/705 | 2023-04-27 | |
https://github.com/nextcloud/server/pull/37252 | 2023-04-27 |
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-3m2f-v8x7-9w99 | 2023-04-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Files Automated Tagging Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" | >= 1.14.0 < 1.14.2 Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" and version " >= 1.14.0 < 1.14.2" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Files Automated Tagging Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" | >= 1.15.0 < 1.15.3 Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" and version " >= 1.15.0 < 1.15.3" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Files Automated Tagging Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" | 1.11.0 Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" and version "1.11.0" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Files Automated Tagging Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" | 1.12.0 Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" and version "1.12.0" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Files Automated Tagging Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" | 1.13.0 Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" and version "1.13.0" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Files Automated Tagging Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" | 1.16.0 Search vendor "Nextcloud" for product "Nextcloud Files Automated Tagging" and version "1.16.0" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 21.0.0 < 21.0.9.11 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 21.0.0 < 21.0.9.11" | enterprise |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 22.0.0 < 22.2.10.11 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 22.0.0 < 22.2.10.11" | enterprise |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 23.0.0 < 23.0.12.6 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 23.0.0 < 23.0.12.6" | enterprise |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 24.0.0 < 24.0.11 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 24.0.0 < 24.0.11" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 24.0.0 < 24.0.11 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 24.0.0 < 24.0.11" | enterprise |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 25.0.0 < 25.0.5 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 25.0.0 < 25.0.5" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 25.0.0 < 25.0.5 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 25.0.0 < 25.0.5" | enterprise |
Affected
|