Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

3233342025202620272028

Недавние уязвимости Nextcloud Server

Количество 456

github логотип

GHSA-cpjv-m49g-h8m9

около 4 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-mc2j-762j-c5hj

около 4 лет назад

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-7xfm-46r7-g8cx

около 4 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-fxf7-m32w-qh93

около 4 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-2c99-9fv7-72hj

около 4 лет назад

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-g265-v379-5vwj

около 4 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVSS3: 6.4
EPSS: Низкий
github логотип

GHSA-w44g-m97f-qr3p

около 4 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-qxf8-5jgm-xwxj

около 4 лет назад

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-v6cm-gq9r-7cpp

около 4 лет назад

Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.

CVSS3: 3.5
EPSS: Низкий
github логотип

GHSA-qv8x-gg84-8259

около 4 лет назад

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-cpjv-m49g-h8m9

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.

CVSS3: 6.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-mc2j-762j-c5hj

Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.

CVSS3: 3.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-7xfm-46r7-g8cx

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-fxf7-m32w-qh93

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-2c99-9fv7-72hj

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-g265-v379-5vwj

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVSS3: 6.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-w44g-m97f-qr3p

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a creation of folders in read-only folders despite lacking permissions issue. Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder. Note that this only affects folders and files that the adversary has at least read-only permissions for.

CVSS3: 4.3
1%
Низкий
около 4 лет назад
github логотип
GHSA-qxf8-5jgm-xwxj

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.

CVSS3: 5.4
1%
Низкий
около 4 лет назад
github логотип
GHSA-v6cm-gq9r-7cpp

Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.

CVSS3: 3.5
1%
Низкий
около 4 лет назад
github логотип
GHSA-qv8x-gg84-8259

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.

CVSS3: 5.4
1%
Низкий
около 4 лет назад

Уязвимостей на страницу


Поделиться