SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-0892

Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.

LOW 3.5EPSS 0.98%

Does this matter?

Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.

Description

Nextcloud Server before 11.0.3 is vulnerable to an improper session handling allowed an application specific password without permission to the files access to the users file.

CVSS 3.1
3.5 LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
EPSS
0.98% probability · 60th percentile
CISA KEV
Not listed
Weakness
CWE-285, CWE-384
Affected
nextcloud/nextcloud server
Source
support@hackerone.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.