CVE Vulnerabilities

CVE-2023-39963

Published: Aug 10, 2023 | Modified: Aug 16, 2023
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 20.0.0 and prior to versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.8, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1, a missing password confirmation allowed an attacker, after successfully stealing a session from a logged in user, to create app passwords for the victim. Nextcloud server versions 25.0.9, 26.0.4, and 27.0.1 and Nextcloud Enterprise Server versions 20.0.14.15, 21.0.9.13, 22.2.10.14, 23.0.12.9, 24.0.12.5, 25.0.9, 26.0.4, and 27.0.1 contain a patch for this issue. No known workarounds are available.

Affected Software

Name Vendor Start Version End Version
Nextcloud_server Nextcloud 20.0.0 (including) 20.0.14.15 (excluding)
Nextcloud_server Nextcloud 21.0.0 (including) 21.0.9.13 (excluding)
Nextcloud_server Nextcloud 22.0.0 (including) 22.2.10.14 (excluding)
Nextcloud_server Nextcloud 23.0.0 (including) 23.0.12.9 (excluding)
Nextcloud_server Nextcloud 24.0.0 (including) 24.0.12.5 (excluding)
Nextcloud_server Nextcloud 25.0.0 (including) 25.0.9 (excluding)
Nextcloud_server Nextcloud 26.0.0 (including) 26.0.4 (excluding)
Nextcloud_server Nextcloud 27.0.0 (including) 27.0.0 (including)

References