CVE-2017-9286: nextcloud package security issues with /srv/www/htdocs
Published Mar 1, 2018
·Updated
The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
Affected Software
1 affected component
openSUSE Leap=42.3
Event History
Mar 1, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2017-9286?
CVE-2017-9286 is considered a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2017-9286?
To fix CVE-2017-9286, update your NextCloud package to the latest secure version available for openSUSE.
3
Who is affected by CVE-2017-9286?
CVE-2017-9286 affects users of NextCloud packaged in openSUSE Leap 42.3.
4
What is the impact of CVE-2017-9286?
The impact of CVE-2017-9286 involves possible privilege escalation from wwwrun user to root during package upgrades.
5
When was CVE-2017-9286 disclosed?
CVE-2017-9286 was disclosed in October 2017.