ZeroHour

CVE-2018-16466

CVSS 3.0
8.1 high
EPSS
<1%p59
Published
()
Modified
Description

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.

Vendors
nextcloud
Products
nextcloud server
Weakness
CWE-284, CWE-273
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.