PT-2017-10693 · Nextcloud · Nextcloud Server

CVE-2017-0892

·

Publicado

2017-05-08

·

Atualizado

2022-09-27

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server versions prior to 11.0.3
Description The issue is related to improper session handling, which allows an application-specific password to access user files without permission. This affects the security of file access for users.
Recommendations For versions prior to 11.0.3, update to version 11.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive files until the update is applied.

Correção

Improper Authorization

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-0892

Produtos afetados

Nextcloud Server