SB2018103042 - Session Fixation in Nextcloud Server



SB2018103042 - Session Fixation in Nextcloud Server

Published: October 30, 2018 Updated: July 17, 2020

Security Bulletin ID SB2018103042
Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Session Fixation (CVE-ID: CVE-2018-16463)

The vulnerability allows a remote privileged user to read and manipulate data.

A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.


Remediation

Install update from vendor's website.