Security Advisory

Back to advisories

Creation of folders in read-only folders despite lacking permissions (NC-SA-2017-002)

5th February 2017

Risk level: Low

CVSS v3 Base Score: 4.1 (AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N)

CWE: Permission Issues (CWE-275)

HackerOne report: 169680

Description

Due to a logical error in the file caching layer an authenticated adversary is able to create empty folders inside a shared folder.

Note that this only affects folders and files that the adversary has at least read-only permissions for.

Affected Software

  • Nextcloud Server < 10.0.2 (CVE-2017-0884)
  • Nextcloud Server < 9.0.55 (CVE-2017-0884)

Action Taken

The file cache operation is now only performed if the file system operation succeeded.

Acknowledgements

The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:


This advisory is licensed CC BY-SA 4.0.