SB2017050807 - Multiple vulnerabilities in Nextcloud Server



SB2017050807 - Multiple vulnerabilities in Nextcloud Server

Published: May 8, 2017 Updated: July 18, 2020

Security Bulletin ID SB2017050807
Severity
Low
Patch available
YES
Number of vulnerabilities 2
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 2 secuirty vulnerabilities.


1) Cross-site scripting (CVE-ID: CVE-2017-0891)

The vulnerability allows a remote authenticated user to read and manipulate data.

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are vulnerable to an inadequate escaping of error messages leading to XSS vulnerabilities in multiple components.


2) Cross-site scripting (CVE-ID: CVE-2017-0893)

The vulnerability allows a remote authenticated user to read and manipulate data.

Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.


Remediation

Install update from vendor's website.