CVE-2017-0885: Infoleak
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0885?
CVE-2017-0885 is classified as a medium severity vulnerability due to potential information disclosure.
How do I fix CVE-2017-0885?
To fix CVE-2017-0885, upgrade to Nextcloud Server version 9.0.55 or later, or version 10.0.2 or later.
What does CVE-2017-0885 expose to attackers?
CVE-2017-0885 allows attackers with access to a write-only share to enumerate existing file and folder names through error messages.
Which versions of Nextcloud Server are affected by CVE-2017-0885?
CVE-2017-0885 affects Nextcloud Server versions prior to 9.0.55 and those from 10.0.0 to 10.0.2.
Is user authentication required to exploit CVE-2017-0885?
Yes, an attacker must have access to a write-only share in order to exploit CVE-2017-0885.