Attachments folder for Text app is accessible on "Files drop" and "Password protected" shares
Package
Server
(Nextcloud)
Affected versions
>= 28.0.0, >= 29.0.0, >= 30.0.0
Patched versions
28.0.11, 29.0.8, 30.0.1
Server
(Nextcloud Enterprise)
>= 25.0.0, >= 26.0.0, >= 27.0.0, >= 28.0.0, >= 29.0.0, >= 30.0.0
25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8, 30.0.1
Impact
After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password.
Patches
It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8 or 30.0.1
Workarounds
References
For more information
If you have any questions or comments about this advisory: