3.6

CVE-2018-16463

A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudNextcloud Server Version < 12.0.8
NextcloudNextcloud Server Version >= 13.0.0 < 13.0.3
NextcloudNextcloud Server Version14.0.0 Updatebeta1
NextcloudNextcloud Server Version14.0.0 Updatebeta2
NextcloudNextcloud Server Version14.0.0 Updatebeta3
NextcloudNextcloud Server Version14.0.0 Updatebeta4
NextcloudNextcloud Server Version14.0.0 Updaterc1
NextcloudNextcloud Server Version14.0.0 Updaterc2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.13% 0.336
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.1 0.5 2.5
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
nvd@nist.gov 3.6 3.9 4.9
AV:N/AC:H/Au:S/C:P/I:P/A:N
CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.