Security Advisory

Back to advisories

Permission increase on re-sharing via OCS API (NC-SA-2017-001)

5th February 2017

Risk level: Medium

CVSS v3 Base Score: 5.4 (AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)

CWE: Permission Issues (CWE-275)

HackerOne report: 169680

Description

A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set.Note that this only affects folders and files that the adversary has at least read-only permissions for.

Affected Software

Action Taken

The permissions are now properly checked on the OCS endpoint.

Resolution

It is recommended that all instances are upgraded to Nextcloud 9.0.55 or 10.0.2.

Acknowledgements

The Nextcloud team thanks the following people for their research and responsible disclosure of the above advisory:


This advisory is licensed CC BY-SA 4.0.