Bugzilla – Bug 1211788
VUL-0: CVE-2023-32318: nextcloud: session mishandling
Last modified: 2024-04-16 08:13:42 UTC
A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other account the previous session would be continued and the attacker would be authenticated as the previously logged in user. https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q8c4-chpj-6v38
Tumbleweed, Factory and devel have 25.0.7. Leap still has the master branch 23 and version 23.0.12. No idea if this is also affected. Major updates are not allowed and an update from 23 to 25 does not work. No idea what I should do.
Whats going on? Can i close?