First published: Wed Apr 05 2017(Updated: )
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Server | <9.0.55 | |
Nextcloud Server | >=10.0.0<10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-0885 is classified as a medium severity vulnerability due to potential information disclosure.
To fix CVE-2017-0885, upgrade to Nextcloud Server version 9.0.55 or later, or version 10.0.2 or later.
CVE-2017-0885 allows attackers with access to a write-only share to enumerate existing file and folder names through error messages.
CVE-2017-0885 affects Nextcloud Server versions prior to 9.0.55 and those from 10.0.0 to 10.0.2.
Yes, an attacker must have access to a write-only share in order to exploit CVE-2017-0885.