Логотип exploitDog
bind:CVE-2016-9464
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2016-9464

Количество 4

Количество 4

ubuntu логотип

CVE-2016-9464

около 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2016-9464

около 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2016-9464

около 8 лет назад

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper aut ...

CVSS3: 4.3
EPSS: Низкий
github логотип

GHSA-r69w-pvjm-xg3v

около 3 лет назад

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.

CVSS3: 4.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2016-9464

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.

CVSS3: 4.3
0%
Низкий
около 8 лет назад
nvd логотип
CVE-2016-9464

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.

CVSS3: 4.3
0%
Низкий
около 8 лет назад
debian логотип
CVE-2016-9464

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper aut ...

CVSS3: 4.3
0%
Низкий
около 8 лет назад
github логотип
GHSA-r69w-pvjm-xg3v

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.

CVSS3: 4.3
0%
Низкий
около 3 лет назад

Уязвимостей на страницу