3.6
CVE-2018-16463
- EPSS 0.55%
- Veröffentlicht 30.10.2018 21:29:00
- Zuletzt bearbeitet 21.11.2024 03:52:48
- Erkennungen
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Nextcloud Server Version < 12.0.8
Nextcloud ≫ Nextcloud Server Version >= 13.0.0 < 13.0.3
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update beta1
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update beta2
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update beta3
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update beta4
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update rc1
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update rc2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.55% | 0.413 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 3.1 | 0.5 | 2.5 |
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
|
| NIST | 3.6 | 3.9 | 4.9 |
AV:N/AC:H/Au:S/C:P/I:P/A:N
|
CWE-384 Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
https://hackerone.com/reports/237184
https://nextcloud.com/security/advisory/?id=NC-SA-2018-013