Beveiligingsadvies

CVE-2017-9286

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2018-03-01 19:00:00
Laatst bijgewerkt 2024-09-16 16:28:16
Toegewezen door microfocus
CVSS-score 7.8
Status PUBLISHED

Beschrijving

The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.