Nextcloud

Approval

4 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 18.09.2026 01:26:04
  • Zuletzt bearbeitet 18.09.2026 20:17:25

The Approval app's approve/reject endpoint is meant to require the file's current etag as a freshness check, preventing an approver from approving or rejecting a file whose contents changed after they reviewed it. The backend only enforced this check...

  • EPSS 0.13%
  • Veröffentlicht 01.06.2026 16:51:34
  • Zuletzt bearbeitet 22.07.2026 07:10:00

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can request approval. This issue has been patched in versi...

  • EPSS 0.36%
  • Veröffentlicht 01.06.2026 16:51:22
  • Zuletzt bearbeitet 22.07.2026 07:10:00

Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to force the system to share a file with approvers. Thi...

  • EPSS 0.31%
  • Veröffentlicht 05.12.2025 17:37:06
  • Zuletzt bearbeitet 09.12.2025 17:22:18

The Nextcloud Approval app allows approval or disapproval of files in the sidebar. Prior to 1.3.1 and 2.5.0, an authenticated user listed as a requester in a workflow can set another user’s file into the “pending approval” without access to the file ...