Nextcloud Server to samohostowany system chmury osobistej. W wersji Nextcloud Server i Enterprise Server poniżej 30.0.9 oraz 31.0.1 nieprawidłowa obsługa ścieżek w groupfolders sprawiła, że aplikacja admin_audit nie logowała prawidłowo wszystkich działań na plikach i folderach wewnątrz groupfolders. Podatność została naprawiona w wersji 30.0.9 i 31.0.1.
▸ Pokaż oryginał (EN)
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:LNextcloud Server
APPNextcloud30.0.0 – 30.0.9 (bez)31.0.0 – 31.0.1 (bez)
Powiązane podatności
Nextcloud Server: brak walidacji scope umożliwia RCE przez workflow
Nextcloud Server — SSRF, ujawnienie plików lub RCE przez podglądy obrazów
Nextcloud Server — obejście ochrony brute-force przez adresy IPv6
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before...
Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the...