SB2018103043 - Improper Check for Dropped Privileges in Nextcloud Server



SB2018103043 - Improper Check for Dropped Privileges in Nextcloud Server

Published: October 30, 2018 Updated: July 17, 2020

Security Bulletin ID SB2018103043
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Check for Dropped Privileges (CVE-ID: CVE-2018-16466)

The vulnerability allows a remote authenticated user to read and manipulate data.

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.


Remediation

Install update from vendor's website.