CVE-2023-35928 - CVE House
Back to Database
Status published High CVE-2023-35928

Nextcloud user scoped external storage can be used to gather credentials of other users

Vulnerability Description

Nextcloud Server is a space for data storage on Nextcloud, a self-hosted productivity playform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 19.0.0 until 19.0.13.9, 20.0.0 until 20.0.14.14, 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0 until 24.0.12.2, 25.0.0 until 25.0.7, and 26.0.0 until 26.0.2, a user could use this functionality to get access to the login credentials of another user and take over their account. This issue has been patched in Nextcloud Server versions 25.0.7 and 26.0.2 and NextCloud Enterprise Server versions 19.0.13.9, 20.0.14.14, 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, and 26.0.2. Three workarounds are available. Disable app files_external. Change config setting "Allow users to mount external storage" to disabled in "Administration" > "External storage" settings `…/index.php/settings/admin/externalstorages`. Change config setting to disallow users to create external storages in "Administration" > "External storage" settings `…/index.php/settings/admin/externalstorages` with the types FTP, Nextcloud, SFTP, and/or WebDAV.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-35928

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

security-advisories
Vulnerable Versions:
Nextcloud Enterprise Server >= 19.0.0, < 19.0.13.9, Nextcloud Enterprise Server >= 20.0.0.0, < 20.0.14.14, Nextcloud Enterprise Server >= 21.0.0.0, < 21.0.9.12, Nextcloud Enterprise Server >= 22.0.0.0, < 22.2.10.12, Nextcloud Enterprise Server >= 23.0.0.0, < 23.0.12.7, Nextcloud Enterprise Server >= 24.0.0.0, < 24.0.12.2, Nextcloud Enterprise Server >= 25.0.0, < 25.0.7 , Nextcloud Enterprise Server >= 26.0.0, < 26.0.2, Nextcloud Server >= 25.0.0, < 25.0.7, Nextcloud Server >= 26.0.0, < 26.0.2

Timeline

Official Publish: June 23rd, 2023
Last Modified: December 5th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.