Cloudreve

Cloudreve

17 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.36%
  • Veröffentlicht 31.07.2026 03:23:33
  • Zuletzt bearbeitet 08.09.2026 20:51:43

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, GET /api/v4/user/search calls SearchActive without adding a StatusActive predicate and serializes matches at RedactLevelUser, allowing any logged-in user to enumerate ema...

  • EPSS 0.38%
  • Veröffentlicht 31.07.2026 02:58:14
  • Zuletzt bearbeitet 08.09.2026 20:51:43

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the WOPI PUT_RELATIVE handler passes X-WOPI-SuggestedTarget to URI.JoinRaw as a path rather than a filename, allowing slash and dot-dot segments to escape the source file...

  • EPSS 0.25%
  • Veröffentlicht 15.07.2026 14:40:24
  • Zuletzt bearbeitet 15.07.2026 18:15:13

Cloudreve is a self-hosted file management and sharing system. From 4.12.0 until 4.16.1, Cloudreve's OAuth access tokens are issued without the OAuth client_id claim, so the JWT verifier does not load token scopes into request context and RequiredSco...

  • EPSS 0.19%
  • Veröffentlicht 15.07.2026 14:38:54
  • Zuletzt bearbeitet 15.07.2026 18:15:13

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send paths such as /dav/%2e%2e/outside.txt because stripPrefix in pkg/webdav/webdav.go joins the decoded requ...

  • EPSS 0.24%
  • Veröffentlicht 15.07.2026 14:37:37
  • Zuletzt bearbeitet 15.07.2026 18:15:13

Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, Cloudreve's remote download workflow accepts user-supplied URLs at POST /api/v4/workflow/download and passes them to the configured downloader without blocking loopback, ...

  • EPSS 0.38%
  • Veröffentlicht 03.04.2026 20:06:21
  • Zuletzt bearbeitet 24.07.2026 22:10:00

Cloudreve is a self-hosted file management and sharing system. Prior to version 4.13.0, the application uses the weak pseudo-random number generator math/rand seeded with time.Now().UnixNano() to generate critical security secrets, including the secr...

Exploit
  • EPSS 0.47%
  • Veröffentlicht 20.09.2022 15:15:10
  • Zuletzt bearbeitet 21.11.2024 07:05:52

Cloudreve versions v1.0.0 through v3.5.3 are vulnerable to Stored Cross-Site Scripting (XSS), via the file upload functionality. A low privileged user will be able to share a file with an admin user, which could lead to privilege escalation.