Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/97287 - Third Party Advisory, VDB Entry | |
References | () https://github.com/nextcloud/server/commit/3387e5d00fcf6b2ea6b285a091e5743f545e7202 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://github.com/nextcloud/server/commit/7289cb5ec0b812992ab0dfb889744b94bc0994f0 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://github.com/nextcloud/server/commit/a5471b4a3e3f30e99e4de39c97c0c3b3c2f1618f - Issue Tracking, Patch, Third Party Advisory | |
References | () https://github.com/nextcloud/server/commit/e2c4f4f9aa11bc92e8f2212cce73841b922187e8 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://hackerone.com/reports/153905 - Exploit, Third Party Advisory | |
References | () https://nextcloud.com/security/advisory/?id=nc-sa-2016-007 - Patch, Vendor Advisory |
Information
Published : 2017-03-28 02:59
Updated : 2024-11-21 03:01
NVD link : CVE-2016-9464
Mitre link : CVE-2016-9464
CVE.ORG link : CVE-2016-9464
JSON object : View
Products Affected
nextcloud
- nextcloud_server
CWE
CWE-285
Improper Authorization