SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9464

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares.

MEDIUM 4.3EPSS 1.62%

Does this matter?

Lower severity and a low EPSS score (1.62%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group.

CVSS 3.0
4.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS
1.62% probability · 75th percentile
CISA KEV
Not listed
Weakness
CWE-285
Affected
nextcloud/nextcloud server
Source
support@hackerone.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.