First published: Thu Sep 15 2022(Updated: )
Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or 1.14.1. There are no known workarounds for this issue
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Files Access Control | <1.12.2 | |
Nextcloud Files Access Control | =1.13.0 | |
Nextcloud Files Access Control | =1.14.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-36075 has been classified as a moderate severity vulnerability.
To fix CVE-2022-36075, update the Nextcloud files access control app to version 1.14.0 or higher.
CVE-2022-36075 affects Nextcloud files access control versions before 1.12.2 and exactly 1.13.0.
Users of the Nextcloud files access control app with limited access permissions can be affected by CVE-2022-36075.
CVE-2022-36075 affects the access control mechanism in Nextcloud files access control, potentially exposing file names to unauthorized users.