Medium severity6.5NVD Advisory· Published Oct 16, 2023· Updated Jun 17, 2026
CVE-2023-45151
CVE-2023-45151
Description
Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who has gained access to the server to potentially elevate their privilege. This issue has been addressed and users are recommended to upgrade their Nextcloud Server to version 25.0.8, 26.0.3 or 27.0.1. There are no known workarounds for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*+ 4 more
- cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*range: >=25.0.0,<25.0.8
- cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*range: >=25.0.0,<25.0.8
- cpe:2.3:a:nextcloud:nextcloud_server:27.0.0:*:*:*:-:*:*:*
- cpe:2.3:a:nextcloud:nextcloud_server:27.0.0:*:*:*:enterprise:*:*:*
- (no CPE)range: before 25.0.8, 26.0.3, or 27.0.1
- Range: >= 25.0.0, < 25.0.8
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/server/pull/38398nvdIssue TrackingPatch
- github.com/nextcloud/security-advisories/security/advisories/GHSA-hhgv-jcg9-p4m9nvdVendor Advisory
- hackerone.com/reports/1994324nvdPermissions Required
News mentions
0No linked articles in our index yet.