CVE-2023-28834: Nextcloud Server is an open source personal cloud server. Ne..
Apr 3, 2023
Apr 10, 2023
Nextcloud Server is an open source personal cloud server. Nextcloud Server 24.0.0 until 24.0.6 and 25.0.0 until 25.0.4, as well as Nextcloud Enterprise Server 23.0.0 until 23.0.11, 24.0.0 until 24.0.6, and 25.0.0 until 25.0.4, have an information disclosure vulnerability. A user was able to get the full data directory path of the Nextcloud server from an API endpoint. By itself this information is not problematic as it can also be guessed for most common setups, but it could speed up other unknown attacks in the future if the information is known. Nextcloud Server 24.0.6 and 25.0.4 and Nextcloud Enterprise Server 23.0.11, 24.0.6, and 25.0.4 contain patches for this issue. There are no known workarounds.
CVSS base metrics
Learn from academy
What is API?
Types of APIs
GraphQL vs REST
REST vs SOAP
GET vs POST
PUT vs POST
GraphQL Authentication and Authorization
Swagger for API Documentation
Explore more from Akto
Be updated about everything related to API Security, new API vulnerabilities, industry news and product updates.
Discover and find tests from Akto's 100+ API Security test library. Choose your template or add a new template to start your API Security testing.
Check out Akto's product documentation for all information related to features and how to use them.