VulnerabilityModified
CVE-2016-9468
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app.
MEDIUM 5.3EPSS 2.08%
Does this matter?
Lower severity and a low EPSS score (2.08%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepresentation of information.
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 2.08% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-451, CWE-284
- Affected
- nextcloud/nextcloud server · owncloud/owncloud
- Source
- support@hackerone.com
References
- https://github.com/nextcloud/server/commit/7350e13113c8ed484727a5c25331ec11d4d59f5fIssue Tracking, Patch, Third Party Advisory
- https://github.com/nextcloud/server/commit/a4cfb3ddc1f4cdb585e05c0e9b2f8e52a0e2ee3eIssue Tracking, Patch, Third Party Advisory
- https://github.com/owncloud/core/commit/96b8afe48570bc70088ccd8f897e9d71997d336eIssue Tracking, Patch, Third Party Advisory
- https://github.com/owncloud/core/commit/bcc6c39ad8c22a00323a114e9c1a0a834983fb35Issue Tracking, Patch, Third Party Advisory
- https://hackerone.com/reports/149798Exploit, Third Party Advisory
- https://nextcloud.com/security/advisory/?id=nc-sa-2016-011Patch, Vendor Advisory
- https://owncloud.org/security/advisory/?id=oc-sa-2016-021Patch, Vendor Advisory
- https://github.com/nextcloud/server/commit/7350e13113c8ed484727a5c25331ec11d4d59f5fIssue Tracking, Patch, Third Party Advisory
- https://github.com/nextcloud/server/commit/a4cfb3ddc1f4cdb585e05c0e9b2f8e52a0e2ee3eIssue Tracking, Patch, Third Party Advisory
- https://github.com/owncloud/core/commit/96b8afe48570bc70088ccd8f897e9d71997d336eIssue Tracking, Patch, Third Party Advisory
- https://github.com/owncloud/core/commit/bcc6c39ad8c22a00323a114e9c1a0a834983fb35Issue Tracking, Patch, Third Party Advisory
- https://hackerone.com/reports/149798Exploit, Third Party Advisory
- https://nextcloud.com/security/advisory/?id=nc-sa-2016-011Patch, Vendor Advisory
- https://owncloud.org/security/advisory/?id=oc-sa-2016-021Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.