VYPR
Medium severity5.5NVD Advisory· Published Mar 30, 2023· Updated Jun 17, 2026

CVE-2023-28643

CVE-2023-28643

Description

Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to {name} (2). It is recommended that the Nextcloud Server is upgraded to 25.0.3 or 24.0.9. Users unable to upgrade should avoid sharing 2 folders with the same name to the same user.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • Nextcloud/Server3 versions
    cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*+ 2 more
    • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*range: >=24.0.0,<24.0.9
    • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*range: >=24.0.0,<24.0.9
    • (no CPE)range: before 25.0.3 or 24.0.9
  • Range: < 24.0.9

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.