← Back

CVE-2023-35927

nvd nist
Published: Jun 23, 2023Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0 until 24.0.12.2, 25.0.0 until 25.0.7, and 26.0.0 until 26.0.2, when two server are registered as trusted servers for each other and successfully exchanged the share secrets, the malicious server could modify or delete VCards in the system addressbook on the origin server. This would impact the available and shown information in certain places, such as the user search and avatar menu. If a manipulated user modifies their own data in the personal settings the entry is fixed again. Nextcloud Server n 25.0.7 and 26.0.2 and Nextcloud Enterprise Server 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, and 26.0.2 contain a patch for this issue. A workaround is available. Remove all trusted servers in the "Administration" > "Sharing" settings `…/index.php/settings/admin/sharing`. Afterwards, trigger a recreation of the local system addressbook with the following `occ dav:sync-system-addressbook`.

Affected (10)

1 product
Nextcloud Server
Configuration A
10 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
From 25.0.0 to 25.0.7
From 26.0.0 to 26.0.2
From 16.0.0 to 19.0.13.9
From 20.0.0 to 20.0.14.14
From 21.0.0 to 21.0.9.12
From 22.0.0 to 22.2.10.12
From 23.0.0 to 23.0.12.7
From 24.0.0 to 24.0.12.2
From 25.0.0 to 25.0.7
From 26.0.0 to 26.0.2

References (6)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.