5th February 2017
Risk level: Medium
CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
CWE: Permission Issues (CWE-275)
HackerOne report: 169680
A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set.Note that this only affects folders and files that the adversary has at least read-only permissions for.
The permissions are now properly checked on the OCS endpoint.
It is recommended that all instances are upgraded to Nextcloud 9.0.55 or 10.0.2.
The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory: