Nextcloud Server before 9.0.55 and 10.0.2 suffers from a Denial of Service attack. Due to an error in the application logic an authenticated adversary may trigger an endless recursion in the application leading to a potential Denial of Service.
The product does not properly control the amount of recursion that takes place, consuming excessive resources, such as allocated memory or the program stack.
Link | Tags |
---|---|
https://nextcloud.com/security/advisory/?id=nc-sa-2017-004 | patch vendor advisory broken link |
https://hackerone.com/reports/174524 | third party advisory |