Nextcloud Server — набор клиент-серверных программ для создания и использования хранилища данных.
Релизный цикл, информация об уязвимостях
График релизов
Количество 456
CVE-2018-3780
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.
CVE-2018-3776
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0. ...
CVE-2018-3776
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.
CVE-2018-3775
Improper Authentication in Nextcloud Server prior to version 12.0.3 wo ...
CVE-2018-3775
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
CVE-2018-3776
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.
CVE-2018-3762
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks ...
CVE-2018-3762
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
CVE-2018-3761
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authent ...
CVE-2018-3761
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано 1 | |
|---|---|---|---|---|
CVE-2018-3780 A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users. | CVSS3: 5.4 | 1% Низкий | около 8 лет назад | |
CVE-2018-3776 Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0. ... | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-3776 Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-3775 Improper Authentication in Nextcloud Server prior to version 12.0.3 wo ... | CVSS3: 8.8 | 1% Низкий | около 8 лет назад | |
CVE-2018-3775 Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication. | CVSS3: 8.8 | 1% Низкий | около 8 лет назад | |
CVE-2018-3776 Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. | CVSS3: 5.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-3762 Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks ... | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-3762 Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to. | CVSS3: 4.3 | 1% Низкий | около 8 лет назад | |
CVE-2018-3761 Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authent ... | CVSS3: 8.1 | 2% Низкий | около 8 лет назад | |
CVE-2018-3761 Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised. | CVSS3: 8.1 | 2% Низкий | около 8 лет назад |
Уязвимостей на страницу