CVE-2023-28644

Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

History

07 Nov 2023, 04:10

Type Values Removed Values Added
Summary Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability. Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is recommended that the Nextcloud Server is upgraded to 25.0.3. There are no known workarounds for this vulnerability.

06 Apr 2023, 19:53

Type Values Removed Values Added
First Time Nextcloud nextcloud Server
Nextcloud
CPE cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
CWE CWE-400 NVD-CWE-noinfo
References (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9wmj-gp8v-477j - (MISC) https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9wmj-gp8v-477j - Vendor Advisory
References (MISC) https://github.com/nextcloud/server/pull/36016 - (MISC) https://github.com/nextcloud/server/pull/36016 - Issue Tracking, Patch
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

30 Mar 2023, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-03-30 19:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-28644

Mitre link : CVE-2023-28644

CVE.ORG link : CVE-2023-28644


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
NVD-CWE-noinfo CWE-400

Uncontrolled Resource Consumption