Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
2017-03-28T02:59:00.840
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nextcloud | nextcloud_server | < 9.0.52 | Yes |
Application | owncloud | owncloud | < 9.0.4 | Yes |