CVE-2016-9468: Medium severity nextcloud server vulnerability
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepresentation of information.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9468?
CVE-2016-9468 is considered a moderate severity vulnerability due to its potential for content spoofing.
How do I fix CVE-2016-9468?
To fix CVE-2016-9468, update Nextcloud Server to version 9.0.54 or higher, or 10.0.1 or higher, and update ownCloud Server to versions 9.0.6 or higher, or 9.1.2 or higher.
What systems are affected by CVE-2016-9468?
CVE-2016-9468 affects Nextcloud Server versions before 9.0.54 and 10.0.1, as well as ownCloud Server versions before 9.0.6 and 9.1.2.
What does CVE-2016-9468 exploit?
CVE-2016-9468 exploits content spoofing vulnerabilities in the DAV app, leading to potential misrepresentation of information.
Is there a patch available for CVE-2016-9468?
Yes, patches are available in the updated versions of Nextcloud and ownCloud to address CVE-2016-9468.