Количество 409
Количество 409
GHSA-fjpp-r368-h9gx
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
GHSA-fjhc-75vv-2hgm
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
GHSA-cpjv-m49g-h8m9
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.
GHSA-cg3p-cjqp-v7hh
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
GHSA-9qxg-6mvx-c4mc
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.
GHSA-92hg-jjmr-6gv2
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
GHSA-84fw-wvq7-7x27
Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.
GHSA-7xfm-46r7-g8cx
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.
GHSA-782m-gpwm-4xfq
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
GHSA-6p7m-f494-cjvp
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
GHSA-6mm6-pp6h-9p36
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
GHSA-6m9p-3vwc-4p47
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
GHSA-67vq-qwwf-fc2h
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
GHSA-63cq-5v5v-47mp
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
GHSA-548f-j4fj-64c5
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.
GHSA-3qm7-9jrc-h4gp
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
GHSA-3j4p-7g9x-w28j
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
GHSA-2v55-qcx6-c482
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
GHSA-2q3r-568x-rqmv
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
GHSA-2c99-9fv7-72hj
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-fjpp-r368-h9gx A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received. | 0% Низкий | около 3 лет назад | ||
GHSA-fjhc-75vv-2hgm Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location. | 0% Низкий | около 3 лет назад | ||
GHSA-cpjv-m49g-h8m9 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service. | CVSS3: 6.5 | 1% Низкий | около 3 лет назад | |
GHSA-cg3p-cjqp-v7hh Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long. | 0% Низкий | около 3 лет назад | ||
GHSA-9qxg-6mvx-c4mc A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users. | CVSS3: 5.4 | 0% Низкий | около 3 лет назад | |
GHSA-92hg-jjmr-6gv2 A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file. | 0% Низкий | около 3 лет назад | ||
GHSA-84fw-wvq7-7x27 Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user. | CVSS3: 5.7 | 0% Низкий | около 3 лет назад | |
GHSA-7xfm-46r7-g8cx Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages. | CVSS3: 4.3 | 1% Низкий | около 3 лет назад | |
GHSA-782m-gpwm-4xfq A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset. | 0% Низкий | около 3 лет назад | ||
GHSA-6p7m-f494-cjvp Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to. | CVSS3: 4.3 | 0% Низкий | около 3 лет назад | |
GHSA-6mm6-pp6h-9p36 Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens. | CVSS3: 8.1 | 0% Низкий | около 3 лет назад | |
GHSA-6m9p-3vwc-4p47 Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured. | 0% Низкий | около 3 лет назад | ||
GHSA-67vq-qwwf-fc2h A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares. | CVSS3: 3.1 | 0% Низкий | около 3 лет назад | |
GHSA-63cq-5v5v-47mp A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer. | 0% Низкий | около 3 лет назад | ||
GHSA-548f-j4fj-64c5 Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys. | CVSS3: 8.1 | 0% Низкий | около 3 лет назад | |
GHSA-3qm7-9jrc-h4gp Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`. | 0% Низкий | около 3 лет назад | ||
GHSA-3j4p-7g9x-w28j A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL. | CVSS3: 6.5 | 0% Низкий | около 3 лет назад | |
GHSA-2v55-qcx6-c482 Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication. | CVSS3: 8.8 | 0% Низкий | около 3 лет назад | |
GHSA-2q3r-568x-rqmv A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files. | CVSS3: 4.1 | 0% Низкий | около 3 лет назад | |
GHSA-2c99-9fv7-72hj Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token. | CVSS3: 4.3 | 1% Низкий | около 3 лет назад |
Уязвимостей на страницу