A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
2018-10-30T21:29:00.510
2024-11-21T03:52:48.227
Modified
CVSSv3.0: 3.1 (LOW)
AV:N/AC:H/Au:S/C:P/I:P/A:N
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | nextcloud | nextcloud_server | < 12.0.8 | Yes |
Application | nextcloud | nextcloud_server | < 13.0.3 | Yes |
Application | nextcloud | nextcloud_server | 14.0.0 | Yes |
Application | nextcloud | nextcloud_server | 14.0.0 | Yes |
Application | nextcloud | nextcloud_server | 14.0.0 | Yes |
Application | nextcloud | nextcloud_server | 14.0.0 | Yes |
Application | nextcloud | nextcloud_server | 14.0.0 | Yes |
Application | nextcloud | nextcloud_server | 14.0.0 | Yes |