Security Advisory

CVE-2017-0885

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-04-05 20:00:00
Last updated 2024-08-05 13:18:06
Assigner hackerone
CVSS score not scored
State PUBLISHED

Description

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.