Логотип exploitDog
product: "nextcloud_server"
Консоль
Логотип exploitDog

exploitDog

product: "nextcloud_server"

Количество 409

Количество 409

github логотип

GHSA-fjpp-r368-h9gx

около 3 лет назад

A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.

EPSS: Низкий
github логотип

GHSA-fjhc-75vv-2hgm

около 3 лет назад

Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.

EPSS: Низкий
github логотип

GHSA-cpjv-m49g-h8m9

около 3 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-cg3p-cjqp-v7hh

около 3 лет назад

Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.

EPSS: Низкий
github логотип

GHSA-9qxg-6mvx-c4mc

около 3 лет назад

A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-92hg-jjmr-6gv2

около 3 лет назад

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

EPSS: Низкий
github логотип

GHSA-84fw-wvq7-7x27

около 3 лет назад

Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.

CVSS3: 5.7
EPSS: Низкий
github логотип

GHSA-7xfm-46r7-g8cx

около 3 лет назад

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-782m-gpwm-4xfq

около 3 лет назад

A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.

EPSS: Низкий
github логотип

GHSA-6p7m-f494-cjvp

около 3 лет назад

Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-6mm6-pp6h-9p36

около 3 лет назад

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-6m9p-3vwc-4p47

около 3 лет назад

Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.

EPSS: Низкий
github логотип

GHSA-67vq-qwwf-fc2h

около 3 лет назад

A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.

CVSS3: 3.1
EPSS: Низкий
github логотип

GHSA-63cq-5v5v-47mp

около 3 лет назад

A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

EPSS: Низкий
github логотип

GHSA-548f-j4fj-64c5

около 3 лет назад

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-3qm7-9jrc-h4gp

около 3 лет назад

Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.

EPSS: Низкий
github логотип

GHSA-3j4p-7g9x-w28j

около 3 лет назад

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-2v55-qcx6-c482

около 3 лет назад

Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-2q3r-568x-rqmv

около 3 лет назад

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVSS3: 4.1
EPSS: Низкий
github логотип

GHSA-2c99-9fv7-72hj

около 3 лет назад

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
github логотип
GHSA-fjpp-r368-h9gx

A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.

0%
Низкий
около 3 лет назад
github логотип
GHSA-fjhc-75vv-2hgm

Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.

0%
Низкий
около 3 лет назад
github логотип
GHSA-cpjv-m49g-h8m9

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.

CVSS3: 6.5
1%
Низкий
около 3 лет назад
github логотип
GHSA-cg3p-cjqp-v7hh

Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.

0%
Низкий
около 3 лет назад
github логотип
GHSA-9qxg-6mvx-c4mc

A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.

CVSS3: 5.4
0%
Низкий
около 3 лет назад
github логотип
GHSA-92hg-jjmr-6gv2

A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.

0%
Низкий
около 3 лет назад
github логотип
GHSA-84fw-wvq7-7x27

Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.

CVSS3: 5.7
0%
Низкий
около 3 лет назад
github логотип
GHSA-7xfm-46r7-g8cx

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.

CVSS3: 4.3
1%
Низкий
около 3 лет назад
github логотип
GHSA-782m-gpwm-4xfq

A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.

0%
Низкий
около 3 лет назад
github логотип
GHSA-6p7m-f494-cjvp

Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
github логотип
GHSA-6mm6-pp6h-9p36

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-6m9p-3vwc-4p47

Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.

0%
Низкий
около 3 лет назад
github логотип
GHSA-67vq-qwwf-fc2h

A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.

CVSS3: 3.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-63cq-5v5v-47mp

A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.

0%
Низкий
около 3 лет назад
github логотип
GHSA-548f-j4fj-64c5

Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.

CVSS3: 8.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-3qm7-9jrc-h4gp

Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.

0%
Низкий
около 3 лет назад
github логотип
GHSA-3j4p-7g9x-w28j

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

CVSS3: 6.5
0%
Низкий
около 3 лет назад
github логотип
GHSA-2v55-qcx6-c482

Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.

CVSS3: 8.8
0%
Низкий
около 3 лет назад
github логотип
GHSA-2q3r-568x-rqmv

A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.

CVSS3: 4.1
0%
Низкий
около 3 лет назад
github логотип
GHSA-2c99-9fv7-72hj

Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.

CVSS3: 4.3
1%
Низкий
около 3 лет назад

Уязвимостей на страницу