Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fxf7-m32w-qh93

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the OC-Total-Length HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the OC-Total-Length HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

EPSS

Процентиль: 60%
0.00401
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-807

Связанные уязвимости

CVSS3: 4.3
nvd
около 8 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

CVSS3: 4.3
debian
около 8 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the ...

EPSS

Процентиль: 60%
0.00401
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20
CWE-807