Improper validation of data passed to JSON encoder (NC-SA-2018-006)
3rd August 2018
Risk level: Medium
CVSS v3 Base Score: 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
CWE: Improper Input Validation (CWE-20)
HackerOne report: 232347
Description
Improper validation of input allowed an attacker to not have their actions logged to the audit log.
Affected Software
- Nextcloud Server < 12.0.3 (2018-3776)
- Nextcloud Server < 11.0.5 (2018-3776)
Action Taken
The error has been fixed.
Resolution
It is recommended that all instances are upgraded to at least Nextcloud 12.0.3.
Acknowledgements
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:
- Zhouyuan Yang - Fortinet's FortiGuard Labs - Vulnerability discovery and disclosure.
This advisory is licensed CC BY-SA 4.0.