A missing check in Nextcloud Server prior to 14.0.0 could give unauthorized access to the previews of single file password protected shares.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Link | Tags |
---|---|
https://nextcloud.com/security/advisory/?id=NC-SA-2018-014 | vendor advisory |
https://hackerone.com/reports/231917 | third party advisory exploit |