Количество 409
Количество 409
GHSA-r63f-25g5-v4wf
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
GHSA-qxf8-5jgm-xwxj
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.
GHSA-qv8x-gg84-8259
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.
GHSA-pv3c-r8vx-j8wm
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.
GHSA-pqcg-83hr-mr43
Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders.
GHSA-mwjc-vmmg-j6vm
A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it.
GHSA-mr7g-84h2-qmm4
A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login.
GHSA-mqg9-fwrm-2gxr
A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation.
GHSA-mjfh-rmmm-2mm7
A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
GHSA-mc2j-762j-c5hj
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.
GHSA-m9wc-h684-m6rq
A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user.
GHSA-jg28-fqcj-8vhj
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
GHSA-jchm-73f8-w72j
Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link.
GHSA-j92w-qfjr-c5j9
A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password.
GHSA-grrj-5c92-774h
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.
GHSA-g8q5-cq4v-2qq7
A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules.
GHSA-g265-v379-5vwj
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for.
GHSA-fxf7-m32w-qh93
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.
GHSA-fw6c-8m99-2qjj
A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events.
GHSA-frc3-rhfw-jxf5
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-r63f-25g5-v4wf An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint. | 1% Низкий | около 3 лет назад | ||
GHSA-qxf8-5jgm-xwxj Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components. | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-qv8x-gg84-8259 Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers. | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-pv3c-r8vx-j8wm Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue. | CVSS3: 5.4 | 1% Низкий | около 3 лет назад | |
GHSA-pqcg-83hr-mr43 Improper Input Validation in Nextcloud Server 15.0.7 allows group admins to create users with IDs of system folders. | 0% Низкий | около 3 лет назад | ||
GHSA-mwjc-vmmg-j6vm A wrong configuration in Nextcloud Server 19.0.1 incorrectly made the user feel the passwordless WebAuthn is also a two factor verification by asking for the PIN of the passwordless WebAuthn but not verifying it. | CVSS3: 6.8 | 0% Низкий | около 3 лет назад | |
GHSA-mr7g-84h2-qmm4 A missing check in Nextcloud Server 17.0.0 allowed an attacker to set up a new second factor when trying to login. | 0% Низкий | около 3 лет назад | ||
GHSA-mqg9-fwrm-2gxr A reflected Cross-Site Scripting vulnerability in Nextcloud Server 16.0.1 was discovered in the svg generation. | CVSS3: 6.1 | 0% Низкий | около 3 лет назад | |
GHSA-mjfh-rmmm-2mm7 A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format. | 0% Низкий | около 3 лет назад | ||
GHSA-mc2j-762j-c5hj Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed. | CVSS3: 3.5 | 0% Низкий | около 3 лет назад | |
GHSA-m9wc-h684-m6rq A wrong check in Nextcloud Server 19 and prior allowed to perform a denial of service attack when resetting the password for a user. | 1% Низкий | около 3 лет назад | ||
GHSA-jg28-fqcj-8vhj A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call. | CVSS3: 7.5 | 1% Низкий | около 3 лет назад | |
GHSA-jchm-73f8-w72j Improper permissions preservation in Nextcloud Server 16.0.1 causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link. | 0% Низкий | около 3 лет назад | ||
GHSA-j92w-qfjr-c5j9 A missing access check in Nextcloud Server prior to 14.0.0 could lead to continued access to password protected link shares when the owner had changed the password. | CVSS3: 5.7 | 0% Низкий | около 3 лет назад | |
GHSA-grrj-5c92-774h Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. | CVSS3: 5.3 | 1% Низкий | около 3 лет назад | |
GHSA-g8q5-cq4v-2qq7 A missing input validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows users to store unlimited data in workflow rules causing load and potential DDoS on later interactions and usage with those rules. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-g265-v379-5vwj Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for. | CVSS3: 6.4 | 0% Низкий | около 3 лет назад | |
GHSA-fxf7-m32w-qh93 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-fw6c-8m99-2qjj A missing check in the Nextcloud Server prior to version 15.0.1 causes leaking of calendar event names when adding or modifying confidential or private events. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-frc3-rhfw-jxf5 Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised. | CVSS3: 8.1 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу