CVE-2017-0887: Input Validation
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the OC-Total-Length HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-0887?
CVE-2017-0887 has a moderate severity rating as it allows authenticated users to bypass quota limitations.
How do I fix CVE-2017-0887?
To fix CVE-2017-0887, update Nextcloud Server to versions 9.0.55 or 10.0.2 or later.
Who is affected by CVE-2017-0887?
CVE-2017-0887 affects all versions of Nextcloud Server prior to 9.0.55 and between 10.0.0 and 10.0.2.
What impact does CVE-2017-0887 have on users?
CVE-2017-0887 allows an authenticated user to exceed their set storage quota, potentially leading to service disruption.
Is CVE-2017-0887 a remote or local vulnerability?
CVE-2017-0887 is a local vulnerability that requires user authentication to exploit.