Описание
Nextcloud iOS before 3.4.2 suffers from an information disclosure vulnerability when searches for sharees utilize the lookup server by default instead of only on the local Nextcloud server unless a global search has been explicitly chosen by the user.
Ссылки
- Third Party Advisory
- ExploitIssue TrackingThird Party Advisory
- Third Party Advisory
- ExploitIssue TrackingThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.4.2 (исключая)
cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:iphone_os:*:*
EPSS
Процентиль: 70%
0.00652
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-200
CWE-200
EPSS
Процентиль: 70%
0.00652
Низкий
6.5 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-200
CWE-200