Users can delete old versions of read-only shared files
Package
Server
(Nextcloud)
Affected versions
>= 26.0.0
>= 27.0.0
>= 28.0.0
Patched versions
26.0.13
27.1.8
28.0.4
Server
(Nextcloud Enterprise)
>= 25.0.0
>= 26.0.0
>= 27.0.0
>= 28.0.0
25.0.13.7
26.0.13
27.1.8
28.0.4
Impact
A malicious user was able to send delete requests for old versions of files they only got shared with read permissions.
Patches
It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.13.7 or 26.0.12 or 27.1.7 or 28.0.3
Workarounds
References
For more information
If you have any questions or comments about this advisory: