CVE-2023-48305
CVSS 3.1 Score 4.4 of 10 (medium)
Details
Summary
CVE-2023-48305 is a vulnerability affecting Nextcloud Server, a data storage solution for the open-source cloud platform Nextcloud. Versions 25.0.0 through 27.1.0, including both Nextcloud Server and Nextcloud Enterprise Server, are impacted if the log level is set to debug. These versions log user passwords in plaintext in the log file, posing a serious security risk if the file is leaked or shared. Patched versions 25.0.11, 26.0.6, and 27.1.0 are available to address this issue. As a temporary solution, adjusting the `loglevel` config setting to 1 or higher (recommended to be higher than 1 in production environments) can prevent password logging.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Nextcloud Server
Affected Vendors
- Nextcloud GmbH