CVE-2017-0892
low
CVSS v3
3.5
CVSS v2
4.3
VIR risk
3.5
Description
Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.
Predictions
Exploit likelihood
45%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: support@hackerone.com — https://nextcloud.com/security/advisory/?id=nc-sa-2017-009
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| nextcloud | nextcloud_server | {"endExcluding":"11.0.3"} | 11.0.3 |
References
CWEs
CWE-285 CWE-384
Verify integrity in audit chain (admin only). AS-IS.