Vulnerability CVE-2023-48301: Information

Description

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.13, 26.0.8, and 27.1.3 of Nextcloud Server and Nextcloud Enterprise Server, an attacker could insert links into circles name that would be opened when clicking the circle name in a search filter. Nextcloud Server and Nextcloud Enterprise Server versions 25.0.13, 26.0.8, and 27.1.3 contain a fix for this issue. As a workaround, disable app circles.

Severity: MEDIUM (5.4) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Published: Nov. 22, 2023
Modified: Nov. 30, 2023
Error type identifier: CWE-79

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
nextcloudsisyphus27.1.4-alt129.0.0-alt1ALT-PU-2023-7786-2331928Fixed
nextcloudsisyphus_e2k27.1.4-alt129.0.0-alt1ALT-PU-2023-8114-1-Fixed
nextcloudsisyphus_loongarch6427.1.4-alt129.0.0-alt1ALT-PU-2023-8099-1-Fixed
nextcloudp1026.0.9-alt0.p10.127.1.4-alt1ALT-PU-2023-7785-2335752Fixed
nextcloudp10_e2k26.0.9-alt0.p10.127.1.4-alt1ALT-PU-2023-7955-1-Fixed
nextcloudp1127.1.4-alt129.0.0-alt1ALT-PU-2023-7786-2331928Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      27.0.0
      End excliding
      27.1.3

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      26.0.0
      End excliding
      26.0.8

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      25.0.0
      End excliding
      25.0.13

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
      Start including
      27.0.0
      End including
      27.1.3

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
      Start including
      26.0.0
      End including
      26.0.8

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
      Start including
      25.0.0
      End including
      25.0.13