CVE-2023-28644

Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

History

21 Nov 2024, 07:55

Type Values Removed Values Added
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9wmj-gp8v-477j - Vendor Advisory () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9wmj-gp8v-477j - Vendor Advisory
References () https://github.com/nextcloud/server/pull/36016 - Issue Tracking, Patch () https://github.com/nextcloud/server/pull/36016 - Issue Tracking, Patch
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 5.7

07 Nov 2023, 04:10

Type Values Removed Values Added
Summary Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability. Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability.

Information

Published : 2023-03-30 19:15

Updated : 2024-11-21 07:55


NVD link : CVE-2023-28644

Mitre link : CVE-2023-28644

CVE.ORG link : CVE-2023-28644


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-400

Uncontrolled Resource Consumption

NVD-CWE-noinfo