« Volver al listado

CVE-2025-66545

Estado: AnalizadaMedia (4.3)—

Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-66545",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-66545",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-12-08T19:55:07.172366Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security-advisories@github.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.5,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.1
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security-advisories@github.com",
      "affectedData": [
        {
          "vendor": "nextcloud",
          "product": "security-advisories",
          "versions": [
            {
              "status": "affected",
              "version": "< 14.0.11"
            },
            {
              "status": "affected",
              "version": ">= 15.0.0-beta1, < 15.3.12"
            },
            {
              "status": "affected",
              "version": ">= 16.0.0, < 16.0.15"
            },
            {
              "status": "affected",
              "version": ">= 17.0.0-beta.1, < 17.0.14"
            },
            {
              "status": "affected",
              "version": ">= 18.0.0-beta.1, < 18.1.8"
            },
            {
              "status": "affected",
              "version": ">= 19.0.0-alpha.1, < 19.1.8"
            },
            {
              "status": "affected",
              "version": ">= 20.0.0, < 20.1.2"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-12-05T18:15:57.803",
  "references": [
    {
      "url": "https://github.com/nextcloud/groupfolders/commit/bbe87ebed8da23e9df4db637a76fbc8d36439d58",
      "tags": [
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nextcloud/groupfolders/issues/4041",
      "tags": [
        "Issue Tracking"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nextcloud/groupfolders/pull/4076",
      "tags": [
        "Issue Tracking",
        "Patch"
      ],
      "source": "security-advisories@github.com"
    },
    {
      "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2vrq-fhmf-c49m",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "security-advisories@github.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security-advisories@github.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-707"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Nextcloud Groupfolders provides admin-configured folders shared by everyone in a group or team. Prior to 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2, a user with read-only permission can restore a file from the trash bin. This vulnerability is fixed in 14.0.11, 15.3.12, 16.0.15, 17.0.14, 18.1.8, 19.1.8, and 20.1.2."
    }
  ],
  "lastModified": "2026-06-17T09:57:00.237",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4ABD858C-8EC4-4507-8A90-9C5949CE38B2",
              "versionEndExcluding": "14.0.11"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "95CD54FB-7784-4855-AB57-62043D1CF549",
              "versionEndExcluding": "15.3.12",
              "versionStartIncluding": "15.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "16939A8A-F224-4A61-8939-ED7204075D4C",
              "versionEndExcluding": "16.0.15",
              "versionStartIncluding": "16.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B05F453B-E12E-495E-BEA3-B7C62680B92D",
              "versionEndExcluding": "17.0.14",
              "versionStartIncluding": "17.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9B89A828-C673-431F-B0D4-73D3BAA6B70A",
              "versionEndExcluding": "18.1.8",
              "versionStartIncluding": "18.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:group_folders:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "19B3F8FA-A80C-4A55-8215-C28C2E432CD3",
              "versionEndExcluding": "20.1.2",
              "versionStartIncluding": "19.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security-advisories@github.com"
}