VYPR
Medium severity6.5NVD Advisory· Published Oct 16, 2023· Updated Jun 17, 2026

CVE-2023-45151

CVE-2023-45151

Description

Nextcloud server is an open source home cloud platform. Affected versions of Nextcloud stored OAuth2 tokens in plaintext which allows an attacker who has gained access to the server to potentially elevate their privilege. This issue has been addressed and users are recommended to upgrade their Nextcloud Server to version 25.0.8, 26.0.3 or 27.0.1. There are no known workarounds for this vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

6
  • Nextcloud/Server5 versions
    cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*+ 4 more
    • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*range: >=25.0.0,<25.0.8
    • cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*range: >=25.0.0,<25.0.8
    • cpe:2.3:a:nextcloud:nextcloud_server:27.0.0:*:*:*:-:*:*:*
    • cpe:2.3:a:nextcloud:nextcloud_server:27.0.0:*:*:*:enterprise:*:*:*
    • (no CPE)range: before 25.0.8, 26.0.3, or 27.0.1
  • Range: >= 25.0.0, < 25.0.8

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.