ALT-PU-2023-1116-1
Closed vulnerabilities
BDU:2023-02153
Уязвимость облачного программного обеспечения для создания и использования хранилища данных Nextcloud, позволяющая нарушителю получить вызвать отказ в обслуживании
BDU:2023-02260
Уязвимость облачного программного обеспечения для создания и использования хранилища данных Nextcloud, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2023-02261
Уязвимость облачного программного обеспечения для создания и использования хранилища данных Nextcloud, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2023-25816
Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired. This issue is patched in 25.0.3 No workaround is available.
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-53q2-cm29-7j83
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-53q2-cm29-7j83
- https://github.com/nextcloud/server/pull/35965
- https://github.com/nextcloud/server/pull/35965
- https://hackerone.com/reports/1820864
- https://hackerone.com/reports/1820864
Modified: 2024-11-21
CVE-2023-28643
Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to `{name} (2)`. It is recommended that the Nextcloud Server is upgraded to 25.0.3 or 24.0.9. Users unable to upgrade should avoid sharing 2 folders with the same name to the same user.
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hhq4-4pr8-wm27
- https://github.com/nextcloud/server/issues/34015
- https://github.com/nextcloud/server/pull/36047
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-hhq4-4pr8-wm27
- https://github.com/nextcloud/server/pull/36047
- https://github.com/nextcloud/server/issues/34015
Modified: 2024-11-21
CVE-2023-28644
Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability.