Security Advisory

Back to advisories

Limitation of app specific password scope can be bypassed (NC-SA-2017-009)

8th May 2017

Risk level: Low

CVSS v3 Base Score: 3 (AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N)

CWE: Improper Authorization (CWE-285)

HackerOne report: 191979


Improper session handling allowed an application specific password without permission to the files access to the users file.

Affected Software

  • Nextcloud Server < 11.0.3 (CVE-2017-0892)

Action Taken

The permission check has been corrected and reviewed.


The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:

  • Mmakosdel - Vulnerability discovery and disclosure.

This advisory is licensed CC BY-SA 4.0.