Welcome to mirror list, hosted at ThFree Co, Russian Federation.

github.com/nextcloud/security-advisories.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoas Schilling <coding@schilljs.com>2021-01-04 19:04:09 +0300
committerJoas Schilling <coding@schilljs.com>2021-01-04 19:04:09 +0300
commit676ad2c21b8441bad201ff022728db34f58aaaf1 (patch)
treeb60512ad086b1e1bb8ddbf725f6b899e9d19a37a
parent45cf278e8fce1df7ac44f7f61e500f569743688f (diff)
Remove invalid website
Signed-off-by: Joas Schilling <coding@schilljs.com>
-rw-r--r--server/nc-sa-2016-004.json3
1 files changed, 1 insertions, 2 deletions
diff --git a/server/nc-sa-2016-004.json b/server/nc-sa-2016-004.json
index 7f819cb..130f347 100644
--- a/server/nc-sa-2016-004.json
+++ b/server/nc-sa-2016-004.json
@@ -19,14 +19,13 @@
"Commits": [
"server/3491400261c1454a9a30d3ec96969573330120cc"
]
- }
+ }
],
"Description":"The WebDAV endpoint was not properly checking the permission on a WebDAV \"COPY\" action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.",
"ActionTaken": "The permission check is now also performed on \"COPY\" actions,",
"Acknowledgment":[
{
"Name":"Kumar Saurabh",
- "Website": "http://www.ksaurabh.net",
"Reason":"Vulnerability discovery and disclosure."
}
],