Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.
The product generates an error message that includes sensitive information about its environment, users, or associated data.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://nextcloud.com/security/advisory/?id=nc-sa-2017-003 | patch vendor advisory broken link |
https://hackerone.com/reports/174524 | third party advisory |