3.6

CVE-2018-16463

A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Nextcloud Server Version < 12.0.8
Nextcloud ≫ Nextcloud Server Version >= 13.0.0 < 13.0.3
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update beta1
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update beta2
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update beta3
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update beta4
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update rc1
Nextcloud ≫ Nextcloud Server Version 14.0.0 Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.55% 0.413
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.1 0.5 2.5
CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N
NIST 3.6 3.9 4.9
AV:N/AC:H/Au:S/C:P/I:P/A:N
CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.

https://hackerone.com/reports/237184
Third Party Advisory
https://nextcloud.com/security/advisory/?id=NC-SA-2018-013
Vendor Advisory