Skip to content

Protect Your Data: Update Recommendations for the Nextcloud Security Vulnerability CVE-2023-32318

Updates & News  ·   ·   ·  Updated on  ·  3 min Reading time

In the world of web hosting and data management, it's important to always stay up to date, especially when it comes to security. Today we want to inform you about a critical security vulnerability discovered in Nextcloud.

The vulnerability, known as CVE-2023-32318, affects the Nextcloud server and the Nextcloud Text app. A flaw in the handling of sessions between the Nextcloud server and the Nextcloud Text app prevents proper session destruction on logout when cookies are not manually cleared. After successfully authenticating with another account, the previous session continues, and the attacker would be authenticated as the previously logged-in user.

Technical background:

Session management is a core part of any web application. It allows user information to be retained across the various requests a user makes during a session. There are many potential security pitfalls in implementing session management, and one of them is the proper destruction of sessions.

In this specific case, the problem occurs when a user logs out but the session data is not properly destroyed. This means the session data, including the user's authentication information, remains on the server and can be exploited by an attacker. If an attacker then successfully authenticates a different session, they are treated as the previously logged-in user, since that user's session data is still present on the server.

The vulnerability affects Nextcloud Server versions from 25.0.2 and from 26.0.0. If you are using one of these versions, you could be affected by the vulnerability. It also affects Nextcloud Enterprise Server versions from 25.0.2 and from 26.0.0.

It is recommended to update the Nextcloud server to version 25.0.6 or 26.0.1. This also applies to the Nextcloud Enterprise Server. As a temporary workaround, you could disable the Nextcloud Text app until you are able to carry out the updates.

The security of your data should always be the top priority. It's essential to stay informed and make sure all your applications are up to date, in order to prevent or fix security vulnerabilities. At Prepaid-Host, we offer web hosting solutions that meet your security requirements. Our server location in Frankfurt am Main ensures that your data is quickly and reliably accessible, which in turn makes your data more secure.

The world of web hosting is constantly moving, and new security threats can appear at any time. But don't worry, we're here to support you. If you have questions or need assistance, don't hesitate to contact us. Together, we can make sure your data stays safe and protected.

Frequently asked questions

What is CVE-2023-32318?
It's a vulnerability in the Nextcloud server and the Nextcloud Text app caused by a flaw in session handling. If a user logs out without manually clearing cookies, the session isn't properly destroyed, so an attacker who then authenticates can end up authenticated as the previously logged-in user.
Which Nextcloud versions are affected?
Nextcloud Server and Nextcloud Enterprise Server versions from 25.0.2 and from 26.0.0.
How can I protect myself?
Update Nextcloud Server (or Enterprise Server) to version 25.0.6 or 26.0.1. As a temporary workaround until you can update, disable the Nextcloud Text app.
Prepaid-Host.com is itself a provider of servers, web hosting and domains, and reports here on its own market. How we handle that is set out in our disclosure statement.