Nextcloud Server — набор клиент-серверных программ для создания и использования хранилища данных.
Релизный цикл, информация об уязвимостях
График релизов
Количество 456
CVE-2018-16465
Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load.
CVE-2018-16465
Missing state in Nextcloud Server prior to 14.0.0 would not enforce th ...
CVE-2018-16464
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.
CVE-2018-16464
A missing access check in Nextcloud Server prior to 14.0.0 could lead ...
CVE-2018-16463
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
CVE-2018-16463
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13 ...
openSUSE-SU-2018:2521-2
Security update for nextcloud
openSUSE-SU-2018:2510-1
Security update for nextcloud
openSUSE-SU-2018:2521-1
Security update for nextcloud
CVE-2018-3780
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-16465 Missing state in Nextcloud Server prior to 14.0.0 would not enforce the use of a second factor at login if the the provider of the second factor failed to load. | CVSS3: 5.3 | 1% Низкий | почти 8 лет назад | |
CVE-2018-16465 Missing state in Nextcloud Server prior to 14.0.0 would not enforce th ... | CVSS3: 5.3 | 1% Низкий | почти 8 лет назад | |
CVE-2018-16464 A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password. | CVSS3: 5.7 | 1% Низкий | почти 8 лет назад | |
CVE-2018-16464 A missing access check in Nextcloud Server prior to 14.0.0 could lead ... | CVSS3: 5.7 | 1% Низкий | почти 8 лет назад | |
CVE-2018-16463 A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares. | CVSS3: 3.1 | 1% Низкий | почти 8 лет назад | |
CVE-2018-16463 A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13 ... | CVSS3: 3.1 | 1% Низкий | почти 8 лет назад | |
openSUSE-SU-2018:2521-2 Security update for nextcloud | 1% Низкий | почти 8 лет назад | ||
openSUSE-SU-2018:2510-1 Security update for nextcloud | 1% Низкий | почти 8 лет назад | ||
openSUSE-SU-2018:2521-1 Security update for nextcloud | 1% Низкий | почти 8 лет назад | ||
CVE-2018-3780 A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users. | CVSS3: 5.4 | 1% Низкий | почти 8 лет назад |
Уязвимостей на страницу