Nextcloud

Nextcloud Server

175 vulnerabilities found.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.28%
  • Published 31.03.2023 23:15:07
  • Last modified 21.11.2024 07:56:08

Nextcloud server is an open source home cloud implementation. In affected versions users that should not be able to download a file can still download an older version and use that for uncontrolled distribution. This issue has been addressed in versi...

  • EPSS 0.74%
  • Published 30.03.2023 19:15:07
  • Last modified 21.11.2024 07:56:07

Nextcloud server is an open source home cloud implementation. In affected versions the generated fallback password when creating a share was using a weak complexity random number generator, so when the sharer did not change it the password could be g...

Warning
  • EPSS 65.51%
  • Published 30.03.2023 19:15:06
  • Last modified 21.11.2024 07:51:36

Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed users to create workflows which are designed to be only available for administrators. Some workflows are designed to be RCE by invok...

Exploit
  • EPSS 0.56%
  • Published 30.03.2023 19:15:06
  • Last modified 21.11.2024 07:55:43

Nextcloud server is an open source home cloud implementation. In affected versions when a recipient receives 2 shares with the same name, while a memory cache is configured, the second share will replace the first one instead of being renamed to `{na...

  • EPSS 0.61%
  • Published 30.03.2023 19:15:06
  • Last modified 21.11.2024 07:55:43

Nextcloud server is an open source home cloud implementation. In releases of the 25.0.x branch before 25.0.3 an inefficient fetch operation may impact server performances and/or can lead to a denial of service. This issue has been addressed and it is...

  • EPSS 0.15%
  • Published 30.03.2023 19:15:06
  • Last modified 21.11.2024 07:56:07

Nextcloud server is an open source home cloud implementation. In affected versions admins of a server were able to upload a logo or a favicon and to provided a file name which was not restricted and could overwrite files in the appdata directory. Adm...

  • EPSS 0.1%
  • Published 27.03.2023 21:15:11
  • Last modified 21.11.2024 07:50:15

Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This issue has bee...

  • EPSS 0.31%
  • Published 27.03.2023 20:15:09
  • Last modified 21.11.2024 07:50:15

Nextcloud server is an open source, personal cloud implementation. In affected versions a malicious user could try to reset the password of another user and then brute force the 62^21 combinations for the password reset token. As of commit `704eb3aa`...

  • EPSS 0.13%
  • Published 22.03.2023 19:15:11
  • Last modified 21.11.2024 07:50:15

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform, and Nextcloud Enterprise Server is the enterprise version of the file server software. In Nextcloud Server versions 25.0.x prior to 25.0.5 and versions 2...

Exploit
  • EPSS 0.14%
  • Published 25.02.2023 00:15:11
  • Last modified 21.11.2024 07:50:15

Nextcloud is an Open Source private cloud software. Versions 25.0.0 and above, prior to 25.0.3, are subject to Uncontrolled Resource Consumption. A user can configure a very long password, consuming more resources on password validation than desired....