Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

3233342025202620272028

Недавние уязвимости Nextcloud Server

Количество 456

github логотип

GHSA-92hg-jjmr-6gv2

около 4 лет назад

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

EPSS: Низкий
github логотип

GHSA-2q3r-568x-rqmv

около 4 лет назад

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-v9r7-gccq-cp4v

около 4 лет назад

A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.

CVSS3: 2.2
EPSS: Низкий
github логотип

GHSA-jg28-fqcj-8vhj

около 4 лет назад

A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-mwjc-vmmg-j6vm

около 4 лет назад

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

CVSS3: 6.8
EPSS: Низкий
github логотип

GHSA-wp2j-2549-fwhp

около 4 лет назад

A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.

EPSS: Низкий
github логотип

GHSA-r63f-25g5-v4wf

около 4 лет назад

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

EPSS: Низкий
github логотип

GHSA-xqxr-66xr-xfq3

около 4 лет назад

An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.

EPSS: Низкий
github логотип

GHSA-3j4p-7g9x-w28j

около 4 лет назад

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-27v9-58mg-8v43

около 4 лет назад

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-92hg-jjmr-6gv2

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

1%
Низкий
около 4 лет назад
github логотип
GHSA-2q3r-568x-rqmv

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVSS3: 4.1
0%
Низкий
около 4 лет назад
github логотип
GHSA-v9r7-gccq-cp4v

A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.

CVSS3: 2.2
0%
Низкий
около 4 лет назад
github логотип
GHSA-jg28-fqcj-8vhj

A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.

CVSS3: 7.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-mwjc-vmmg-j6vm

A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.

CVSS3: 6.8
1%
Низкий
около 4 лет назад
github логотип
GHSA-wp2j-2549-fwhp

A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.

1%
Низкий
около 4 лет назад
github логотип
GHSA-r63f-25g5-v4wf

An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.

2%
Низкий
около 4 лет назад
github логотип
GHSA-xqxr-66xr-xfq3

An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF.

1%
Низкий
около 4 лет назад
github логотип
GHSA-3j4p-7g9x-w28j

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

CVSS3: 6.5
2%
Низкий
около 4 лет назад
github логотип
GHSA-27v9-58mg-8v43

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться