Bug 1212712 (CVE-2023-35171)

Summary: VUL-0: CVE-2023-35171: NextCloud: Open redirect on "Unsupported browser" warning
Product: [Novell Products] SUSE Security Incidents Reporter: Cathy Hu <cathy.hu>
Component: IncidentsAssignee: Eric Schirra <ecsos>
Status: RESOLVED INVALID QA Contact: Security Team bot <security-team>
Severity: Normal    
Priority: P3 - Medium CC: security-team
Version: unspecified   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/370436/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Cathy Hu 2023-06-26 08:42:25 UTC
CVE-2023-35171

NextCloud Server and NextCloud Enterprise Server provide file storage for
Nextcloud, a self-hosted productivity platform. Starting in version 26.0.0 and
prior to version 26.0.2, an attacker could supply a URL that redirects an
unsuspecting victim from a legitimate domain to an attacker's site. Nextcloud
Server and Nextcloud Enterprise Server 26.0.2 contain a patch for this issue. No
known workarounds are available.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-35171
https://bugzilla.redhat.com/show_bug.cgi?id=2217310
https://www.cve.org/CVERecord?id=CVE-2023-35171
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h353-vvwv-j2r4
https://github.com/nextcloud/server/pull/38194
https://hackerone.com/reports/1977222
Comment 1 Cathy Hu 2023-06-26 08:42:37 UTC
Affected:
- openSUSE:Backports:SLE-15-SP4/nextcloud  23.0.5
- openSUSE:Factory/nextcloud               26.0.3
Comment 2 Eric Schirra 2023-06-26 10:02:14 UTC
Please check again.
At least 26.0.3, i.e. Factory, is not affected.
Comment 3 Cathy Hu 2023-06-26 11:04:39 UTC
closing, not affected