Количество 2
Количество 2
CVE-2026-62323
Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or compromised WOPI viewer with a view session to forge the token suffix and invoke WOPI write routes for the underlying file. This issue is fixed in version 4.17.0.
GHSA-c3jm-gv5r-9wcp
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-62323 Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI access token and does not enforce the requested viewer action, allowing a malicious or compromised WOPI viewer with a view session to forge the token suffix and invoke WOPI write routes for the underlying file. This issue is fixed in version 4.17.0. | CVSS3: 6.3 | 0% Низкий | 15 дней назад | |
GHSA-c3jm-gv5r-9wcp Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored | CVSS3: 6.3 | 0% Низкий | 21 день назад |
Уязвимостей на страницу