Potential share collision for recipients when caching is enabled
Package
Server
(Nextcloud)
Affected versions
>= 24.0.0, >= 25.0.0
Patched versions
24.0.9, 25.0.3
Server
(Nextcloud Enterprise)
>= 24.0.0, >= 25.0.0
24.0.9, 25.0.3
Impact
When a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to
… (2)Patches
It is recommended that the Nextcloud Server is upgraded to 25.0.3 or 24.0.9.
It is recommended that the Nextcloud Enterprise Server is upgraded to 25.0.3 or 24.0.9.
Workarounds
Avoid sharing 2 folders with the same name to the same user.
References
For more information
If you have any questions or comments about this advisory: