NextCloud Server v25-26 VCard Delete via Trusted Servers
CVE-2023-35927 Published on June 23, 2023
Nextcloud system addressbooks can be modified by malicious trusted server
NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity platform. In NextCloud Server versions 25.0.0 until 25.0.7 and 26.0.0 until 26.0.2 and Nextcloud Enterprise Server versions 21.0.0 until 21.0.9.12, 22.0.0 until 22.2.10.12, 23.0.0 until 23.0.12.7, 24.0.0 until 24.0.12.2, 25.0.0 until 25.0.7, and 26.0.0 until 26.0.2, when two server are registered as trusted servers for each other and successfully exchanged the share secrets, the malicious server could modify or delete VCards in the system addressbook on the origin server. This would impact the available and shown information in certain places, such as the user search and avatar menu. If a manipulated user modifies their own data in the personal settings the entry is fixed again.
Nextcloud Server n 25.0.7 and 26.0.2 and Nextcloud Enterprise Server 21.0.9.12, 22.2.10.12, 23.0.12.7, 24.0.12.2, 25.0.7, and 26.0.2 contain a patch for this issue. A workaround is available. Remove all trusted servers in the "Administration" > "Sharing" settings `/index.php/settings/admin/sharing`. Afterwards, trigger a recreation of the local system addressbook with the following `occ dav:sync-system-addressbook`.
Vulnerability Analysis
CVE-2023-35927 can be exploited with network access, requires user interaction and a small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, a high impact on integrity, and a small impact on availability.
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2023-35927 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2023-35927
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2023-35927 are published in these products:
Affected Versions
nextcloud security-advisories:- Version Nextcloud Server >= 25.0.0, < 25.0.7 is affected.
- Version Nextcloud Server >= 26.0.0, < 26.0.2 is affected.
- Version Nextcloud Enterprise Server >= 25.0.0, < 25.0.7 is affected.
- Version Nextcloud Enterprise Server >= 26.0.0, < 26.0.2 is affected.
- Version Nextcloud Enterprise Server >= 21.0.0, < 21.0.9.12 is affected.
- Version Nextcloud Enterprise Server >= 22.0.0, < 22.2.10.12 is affected.
- Version Nextcloud Enterprise Server >= 23.0.0, < 23.0.12.7 is affected.
- Version Nextcloud Enterprise Server >= 24.0.0, < 24.0.12.2 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.