Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
Link | Tags |
---|---|
https://hackerone.com/reports/719426 | third party advisory |
https://nextcloud.com/security/advisory/?id=NC-SA-2019-012 | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.html | vendor advisory |
http://lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.html | vendor advisory |