VYPR

security-advisories

by Nextcloud

Source repositories

CVEs (233)

  • CVE-2023-35928HigJun 23, 2023
    risk 0.00cvss 8.4epss 0.01

    Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 19.0.0 until 19.0.13.9, 20.0.0 until 20.0.14.14, 21.0.0 until…

  • CVE-2023-35927HigJun 23, 2023
    risk 0.00cvss 7.6epss 0.01

    NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until…

  • CVE-2023-35173MedJun 23, 2023
    risk 0.00cvss 5.7epss 0.00

    Nextcloud End-to-end encryption app provides all the necessary APIs to implement End-to-End encryption on the client side. By providing an invalid meta data file, an attacker can make previously dropped files inaccessible. It is recommended that the Nextcloud End-to-end…

  • CVE-2023-35172HigJun 23, 2023
    risk 0.00cvss 8.7epss 0.01

    NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until…

  • CVE-2023-35171MedJun 23, 2023
    risk 0.00cvss 4.1epss 0.01

    NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. Starting in version 26.0.0 and prior to version 26.0.2, an attacker could supply a URL that redirects an unsuspecting victim from a legitimate domain to an…

  • CVE-2023-32320HigJun 22, 2023
    risk 0.00cvss 8.7epss 0.01

    Nextcloud Server is a data storage system for Nextcloud, a self-hosted productivity platform. When multiple requests are sent in parallel, all of them were executed even if the amount of faulty requests succeeded the limit by the time the response was sent to the client. This…

  • CVE-2023-33183LowMay 30, 2023
    risk 0.00cvss 2.6epss 0.00

    Calendar app for Nextcloud easily sync events from various devices with your Nextcloud. Some internal paths of the website are disclosed when the SMTP server is unavailable. It is recommended that the Calendar app is updated to 3.5.5 or 4.2.3

  • CVE-2023-33182NonMay 30, 2023
    risk 0.00cvss 0.0epss 0.01

    Contacts app for Nextcloud easily syncs contacts from various devices with your Nextcloud and allows editing. The unsanitized SVG is converted to a JavaScript blob (in memory data) that the Avatar can't render. Due to this constellation the missing sanitization does not seem to…

  • CVE-2023-33184LowMay 27, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Mail is a mail app in Nextcloud. A blind SSRF attack allowed to send GET requests to services running in the same web server. It is recommended that the Mail app is update to version 3.02, 2.2.5 or 1.15.3.

  • CVE-2023-32319HigMay 26, 2023
    risk 0.00cvss 8.1epss 0.01

    Nextcloud server is an open source personal cloud implementation. Missing brute-force protection on the WebDAV endpoints via the basic auth header allowed to brute-force user credentials when the provided user name was not an email address. Users from version 24.0.0 onward are…

  • CVE-2023-32318HigMay 26, 2023
    risk 0.00cvss 7.2epss 0.00

    Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other…

  • CVE-2023-32074HigMay 25, 2023
    risk 0.00cvss 8.0epss 0.01

    user_oidc app is an OpenID Connect user backend for Nextcloud. Authentication can be broken/bypassed in user_oidc app. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.2

  • CVE-2023-28847LowApr 25, 2023
    risk 0.00cvss 3.1epss 0.01

    Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. In Nextcloud Server 24.0.0 prior to 24.0.11 and 25.0.0 prior to 25.0.5; as well as Nextcloud Server Enterprise 23.0.0 prior to 23.0.12.6, 24.0.0 prior to 24.0.11, and 25.0.0 prior to…

  • CVE-2023-30540LowApr 17, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Talk is a chat, video & audio call extension for Nextcloud. In affected versions a user that was added later to a conversation can use this information to get access to data that was deleted before they were added to the conversation. This issue has been patched in…

  • CVE-2023-30539MedApr 17, 2023
    risk 0.00cvss 6.5epss 0.01

    Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that…

  • CVE-2023-29000MedApr 4, 2023
    risk 0.00cvss 5.4epss 0.00

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.7.0, by trusting that the server will return a certificate that belongs to the keypair of the user, a malicious server could get the desktop…

  • CVE-2023-28999MedApr 4, 2023
    risk 0.00cvss 6.9epss 0.01

    Nextcloud is an open-source productivity platform. In Nextcloud Desktop client 3.0.0 until 3.8.0, Nextcloud Android app 3.13.0 until 3.25.0, and Nextcloud iOS app 3.0.5 until 4.8.0, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can…

  • CVE-2023-28998MedApr 4, 2023
    risk 0.00cvss 6.7epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can gain full access to an end-to-end encrypted folder. They can decrypt files, recover the folder…

  • CVE-2023-28997MedApr 4, 2023
    risk 0.00cvss 6.7epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server. Starting with version 3.0.0 and prior to version 3.6.5, a malicious server administrator can recover and modify the contents of end-to-end encrypted files. Users should upgrade the Nextcloud…

  • CVE-2023-28848MedApr 4, 2023
    risk 0.00cvss 4.8epss 0.00

    user_oidc is the OIDC connect user backend for Nextcloud, an open source collaboration platform. A vulnerability in versions 1.0.0 until 1.3.0 effectively allowed an attacker to bypass the state protection as they could just copy the expected state token from the first request…

Page 6 of 12