Nextcloud server 12.0.5App password scope can be changed for other users
Permission increase on re-sharing via OCS API (NC-SA-2017-001)
5th February 2017
Risk level: Medium
CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
HackerOne report: 169680
A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set.
Note that this only affects folders and files that the adversary has at least read-only permissions for.
- Nextcloud Server < 10.0.2 (CVE-2017-0883)
- Nextcloud Server < 9.0.55 (CVE-2017-0883)
The permissions are now properly checked on the OCS endpoint.
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:
This advisory is licensed CC BY-SA 4.0.