Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-30539


Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to 24.0.11 or 25.0.5, the Nextcloud Enterprise Server to 21.0.9.11, 22.2.10.11, 23.0.12.6, 24.0.11 or 25.0.5, and the Nextcloud Files automated tagging app to 1.11.1, 1.12.1, 1.13.1, 1.14.2, 1.15.3 or 1.16.1. Users unable to upgrade should disable all workflow related apps. Users are advised to upgrade.


Published

2023-04-17T22:15:10.210

Last Modified

2024-11-21T08:00:22.943

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud nextcloud_files_automated_tagging < 1.14.2 Yes
Application nextcloud nextcloud_files_automated_tagging < 1.15.3 Yes
Application nextcloud nextcloud_files_automated_tagging 1.11.0 Yes
Application nextcloud nextcloud_files_automated_tagging 1.12.0 Yes
Application nextcloud nextcloud_files_automated_tagging 1.13.0 Yes
Application nextcloud nextcloud_files_automated_tagging 1.16.0 Yes
Application nextcloud nextcloud_server < 21.0.9.11 Yes
Application nextcloud nextcloud_server < 22.2.10.11 Yes
Application nextcloud nextcloud_server < 23.0.12.6 Yes
Application nextcloud nextcloud_server < 24.0.11 Yes
Application nextcloud nextcloud_server < 24.0.11 Yes
Application nextcloud nextcloud_server < 25.0.5 Yes
Application nextcloud nextcloud_server < 25.0.5 Yes

References