SB2018103042 - Session Fixation in Nextcloud Server
Published: October 30, 2018 Updated: July 17, 2020
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Session Fixation (CVE-ID: CVE-2018-16463)
CWE-ID: CWE-384 - Session Fixation
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a remote privileged user to read and manipulate data.
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
Remediation
Install update from vendor's website.