Количество 413
Количество 413
GHSA-fjpp-r368-h9gx
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
GHSA-fjhc-75vv-2hgm
Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location.
GHSA-cpjv-m49g-h8m9
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.
GHSA-cg3p-cjqp-v7hh
Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long.
GHSA-9qxg-6mvx-c4mc
A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.
GHSA-92hg-jjmr-6gv2
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
GHSA-84fw-wvq7-7x27
Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.
GHSA-7xfm-46r7-g8cx
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.
GHSA-782m-gpwm-4xfq
A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset.
GHSA-6p7m-f494-cjvp
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
GHSA-6mm6-pp6h-9p36
Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
GHSA-6m9p-3vwc-4p47
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
GHSA-67vq-qwwf-fc2h
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
GHSA-63cq-5v5v-47mp
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
GHSA-548f-j4fj-64c5
Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys.
GHSA-3qm7-9jrc-h4gp
Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`.
GHSA-3j4p-7g9x-w28j
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
GHSA-2v55-qcx6-c482
Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.
GHSA-2q3r-568x-rqmv
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
GHSA-2c99-9fv7-72hj
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
---|---|---|---|---|
GHSA-fjpp-r368-h9gx A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received. | 0% Низкий | больше 3 лет назад | ||
GHSA-fjhc-75vv-2hgm Missing escaping of HTML in the Updater of Nextcloud 15.0.5 allowed a reflected XSS when starting the updater from a malicious location. | 0% Низкий | больше 3 лет назад | ||
GHSA-cpjv-m49g-h8m9 Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service. | CVSS3: 6.5 | 1% Низкий | больше 3 лет назад | |
GHSA-cg3p-cjqp-v7hh Dangling remote share attempts in Nextcloud 16 allow a DNS pollution when running long. | 0% Низкий | больше 3 лет назад | ||
GHSA-9qxg-6mvx-c4mc A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users. | CVSS3: 5.4 | 0% Низкий | больше 3 лет назад | |
GHSA-92hg-jjmr-6gv2 A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file. | 0% Низкий | больше 3 лет назад | ||
GHSA-84fw-wvq7-7x27 Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user. | CVSS3: 5.7 | 0% Низкий | больше 3 лет назад | |
GHSA-7xfm-46r7-g8cx Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages. | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад | |
GHSA-782m-gpwm-4xfq A bug in Nextcloud Server 15.0.2 causes pending 2FA logins to not be correctly expired when the password of the user is reset. | 0% Низкий | больше 3 лет назад | ||
GHSA-6p7m-f494-cjvp Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to. | CVSS3: 4.3 | 0% Низкий | больше 3 лет назад | |
GHSA-6mm6-pp6h-9p36 Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens. | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад | |
GHSA-6m9p-3vwc-4p47 Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured. | 0% Низкий | больше 3 лет назад | ||
GHSA-67vq-qwwf-fc2h A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares. | CVSS3: 3.1 | 0% Низкий | больше 3 лет назад | |
GHSA-63cq-5v5v-47mp A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer. | 0% Низкий | больше 3 лет назад | ||
GHSA-548f-j4fj-64c5 Insufficient protection of the server-side encryption keys in Nextcloud Server 19.0.1 allowed an attacker to replace the encryption keys. | CVSS3: 8.1 | 0% Низкий | больше 3 лет назад | |
GHSA-3qm7-9jrc-h4gp Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`. | 0% Низкий | больше 3 лет назад | ||
GHSA-3j4p-7g9x-w28j A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL. | CVSS3: 6.5 | 0% Низкий | больше 3 лет назад | |
GHSA-2v55-qcx6-c482 Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication. | CVSS3: 8.8 | 0% Низкий | больше 3 лет назад | |
GHSA-2q3r-568x-rqmv A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files. | CVSS3: 4.1 | 0% Низкий | больше 3 лет назад | |
GHSA-2c99-9fv7-72hj Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token. | CVSS3: 4.3 | 1% Низкий | больше 3 лет назад |
Уязвимостей на страницу