漏洞标题
在 Nextcloud 服务器上创建公共共享时,删除权限不会保存
漏洞描述信息
在Nextcloud服务器上创建公共分享时,删除权限不会被保存
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
漏洞类别
N/A
漏洞标题
Delete permissions are not saved when creating public share in Nextcloud server
漏洞描述信息
Nextcloud server is an open source, personal cloud implementation. In versions from 24.0.0 and before 24.0.9 a user could escalate their permissions to delete files they were not supposed to deletable but only viewed or downloaded. This issue has been addressed andit is recommended that the Nextcloud Server is upgraded to 24.0.9. There are no known workarounds for this vulnerability.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
漏洞类别
权限预留不恰当
漏洞标题
Nextcloud 安全漏洞
漏洞描述信息
Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud 24.0.9之前版本存在安全漏洞,该漏洞源于用户可以升级他们的权限以删除他们只能查看或下载的文件。
CVSS信息
N/A
漏洞类别
其他