nextcloud / nextcloudpi

📦 Build code for NextcloudPi: Raspberry Pi, Odroid, Rock64, curl installer...
https://nextcloudpi.com
2.52k stars 295 forks source link

CVE-2023-48239 in nextcloud server #1854

Closed Colfenor closed 5 months ago

Colfenor commented 10 months ago

Heyo,

in the nextcloud server project a high severe CVE has been reported:

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-f962-hw26-g267

which recommends that the Nextcloud Server is upgraded to quote 25.0.13, 26.0.8 or 27.1.3.

Is there an ETA on when to release a new docker image on the hub with the upstream merged patch ?

As of now the latest version is from 26 July 2023, 4 months ago. https://hub.docker.com/r/ownyourbits/nextcloudpi

greetings !

REAPERSbattlecry commented 10 months ago

The nextcloudpi-docker-version is EOL at the moment. Look here.

So if you are still on docker it is the best to migrate to another ncp instance.

theCalcaholic commented 5 months ago

@REAPERSbattlecry is right, unfortunately. You can always try to update to specific Nextcloud versions manually, but they will not be tested.