Improper validation of data passed to JSON encoder (NC-SA-2018-006)
3rd August 2018
Risk level: Medium
CVSS v3 Base Score: 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
HackerOne report: 232347
Improper validation of input allowed an attacker to not have their actions logged to the audit log.
- Nextcloud Server < 12.0.3 (2018-3776)
- Nextcloud Server < 11.0.5 (2018-3776)
The error has been fixed.
It is recommended that all instances are upgraded to at least Nextcloud 12.0.3.
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:
- Zhouyuan Yang - Fortinet's FortiGuard Labs - Vulnerability discovery and disclosure.
This advisory is licensed CC BY-SA 4.0.