Full path of data directory exposed to users
Package
Server
(Nextcloud)
Affected versions
>= 24.0.0, >= 25.0.0
Patched versions
24.0.10, 25.0.4
Server
(Nextcloud Enterprise)
>= 23.0.0, >= 24.0.0, >= 25.0.0
23.0.14, 24.0.10, 25.0.4
Impact
A user was able to get the full data directory path of the Nextcloud server from an API endpoint. By itself this information is not problematic as it can also be guessed for most common setups, but it could speed up other unknown attacks in the future if the information is known.
Patches
It is recommended that the Nextcloud Server is upgraded to 22.2.11 or 23.0.11 or 24.0.6
It is recommended that the Nextcloud Enterprise Server is upgraded to 22.2.11 or 23.0.11 or 24.0.6
Workarounds
References
For more information
If you have any questions or comments about this advisory: