Nextcloud server 12.0.5App password scope can be changed for other users
Share tokens for public calendars disclosed (NC-SA-2017-011)
8th May 2017
Risk level: Medium
CVSS v3 Base Score: 4.3 (AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N)
HackerOne report: 218876
A logical error caused disclosure of valid share tokens for public calendars. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.
- Nextcloud Server < 11.0.3 (CVE-2017-0894)
The error has been fixed and regression tests been added.
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:
- Lukas Reschke - Nextcloud GmbH (firstname.lastname@example.org) - Vulnerability discovery and disclosure.
This advisory is licensed CC BY-SA 4.0.