Vulnerability CVE-2023-48304: Information

Description

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Enterprise Server, an attacker could enable and disable the birthday calendar for any user on the same server. Nextcloud Server 25.0.11, 26.0.6, and 27.1.0 and Nextcloud Enterprise Server 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11, 26.0.6, and 27.1.0 contain patches for this issue. No known workarounds are available.

Severity: MEDIUM (4.3) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Published: Nov. 22, 2023
Modified: Dec. 1, 2023
Error type identifier: CWE-639

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
nextcloudsisyphus27.1.4-alt129.0.2-alt1ALT-PU-2023-7786-2331928Fixed
nextcloudsisyphus_e2k27.1.4-alt129.0.0-alt1ALT-PU-2023-8114-1-Fixed
nextcloudsisyphus_loongarch6427.1.4-alt129.0.0-alt1ALT-PU-2023-8099-1-Fixed
nextcloudp1026.0.9-alt0.p10.127.1.4-alt1ALT-PU-2023-7785-2335752Fixed
nextcloudp10_e2k26.0.9-alt0.p10.127.1.4-alt1ALT-PU-2023-7955-1-Fixed
nextcloudp1127.1.4-alt129.0.0-alt1ALT-PU-2023-7786-2331928Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      23.0.0
      End excliding
      23.0.12.11

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      24.0.0
      End excliding
      24.0.12.7

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      26.0.0
      End excliding
      26.0.6

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
      Start including
      26.0.0
      End excliding
      26.0.6

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
      Start including
      25.0.0
      End excliding
      25.0.11

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      25.0.0
      End excliding
      25.0.11

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      27.0.0
      End excliding
      27.1.0

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
      Start including
      27.0.0
      End excliding
      27.1.0

      cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
      Start including
      22.0.0
      End including
      22.2.10.16