Описание
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. It is recommended that the Nextcloud Richdocuments app is upgraded to either 3.8.4 or 4.2.1 to resolve. For users unable to upgrade it is recommended that the Richdocuments application be disabled.
Ссылки
- Third Party Advisory
- Third Party Advisory
- Permissions RequiredThird Party Advisory
- Third Party Advisory
- Third Party Advisory
- Permissions RequiredThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 3.8.4 (исключая)Версия от 4.0.0 (включая) до 4.2.1 (исключая)
Одно из
cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*
EPSS
Процентиль: 59%
0.00384
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
CWE-770
EPSS
Процентиль: 59%
0.00384
Низкий
5.3 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-200
CWE-770