CVE-2023-32318 (https://github.com/nextcloud/security-advisories/security/advisories/GHSA-q8c4-chpj-6v38): Nextcloud server provides a home for data. A regression in the session handling between Nextcloud Server and the Nextcloud Text app prevented a correct destruction of the session on logout if cookies were not cleared manually. After successfully authenticating with any other account the previous session would be continued and the attacker would be authenticated as the previously logged in user. It is recommended that the Nextcloud Server is upgraded to 25.0.6 or 26.0.1.
I asked for 25.0.7 stabilization in bug 911410 and 26.0 is cleaned (only 26.0.4 left in tree now)
The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f77024d3308e9213d3473c1b5a955c95bf315564 commit f77024d3308e9213d3473c1b5a955c95bf315564 Author: Bernard Cafarelli <voyageur@gentoo.org> AuthorDate: 2023-07-31 22:20:08 +0000 Commit: Bernard Cafarelli <voyageur@gentoo.org> CommitDate: 2023-07-31 22:20:08 +0000 www-apps/nextcloud: drop 25.0.4 Bug: https://bugs.gentoo.org/904941 Bug: https://bugs.gentoo.org/907268 Signed-off-by: Bernard Cafarelli <voyageur@gentoo.org> www-apps/nextcloud/Manifest | 1 - www-apps/nextcloud/nextcloud-25.0.4.ebuild | 43 ------------------------------ 2 files changed, 44 deletions(-)
Thanks!