Permission increase on re-sharing via OCS API (NC-SA-2017-001)
5th February 2017
Risk level: Medium
CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
HackerOne report: 169680
A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set.Note that this only affects folders and files that the adversary has at least read-only permissions for.
- Nextcloud Server < 10.0.2 (CVE-2017-0883)
- Nextcloud Server < 9.0.55 (CVE-2017-0883)
The permissions are now properly checked on the OCS endpoint.
It is recommended that all instances are upgraded to Nextcloud 9.0.55 or 10.0.2.
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:
This advisory is licensed CC BY-SA 4.0.