CVE-2018-16463: Low severity nextcloud server vulnerability
Published Oct 30, 2018
·Updated
A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.
Affected Software
8 affected components
Nextcloud Server<12.0.8
Nextcloud Server>=13.0.0<13.0.3
Nextcloud Server=14.0.0-beta1
Nextcloud Server=14.0.0-beta2
Nextcloud Server=14.0.0-beta3
Nextcloud Server=14.0.0-beta4
Nextcloud Server=14.0.0-rc1
Nextcloud Server=14.0.0-rc2
Event History
Oct 30, 2018
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2018-16463?
CVE-2018-16463 has been categorized as a medium severity vulnerability.
2
How do I fix CVE-2018-16463?
To fix CVE-2018-16463, you should update your Nextcloud Server to version 14.0.0 or later, or to versions 13.0.3 and 12.0.8.
3
What applications are affected by CVE-2018-16463?
CVE-2018-16463 affects Nextcloud Server versions prior to 14.0.0, 13.0.3, and 12.0.8.
4
What vulnerabilities are associated with CVE-2018-16463?
CVE-2018-16463 is linked to session fixation vulnerabilities that may allow unauthorized access to password protected shares.
5
When was CVE-2018-16463 discovered?
CVE-2018-16463 was reported in 2018, reflecting vulnerabilities in earlier versions of Nextcloud Server.