CVE-2017-0885

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud:*:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:nextcloud:10.0.2:*:*:*:*:*:*:*

Information

Published : 2017-04-05 20:59

Updated : 2019-10-09 23:21


NVD link : CVE-2017-0885

Mitre link : CVE-2017-0885


JSON object : View

Products Affected

nextcloud

  • nextcloud
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor