The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
2018-03-01T20:29:01.070
2024-11-21T03:35:45.667
Modified
CVSSv3.0: 7.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0