Users can modify tags on files that do not belong to them
Package
Server
(Nextcloud)
Affected versions
31.0.0
Patched versions
31.0.1
Server
(Nextcloud Enterprise)
31.0.0
31.0.1
Impact
Non-privileged users can modify tags on files they should not have access to via bulk tagging.
Patches
It is recommended that the Nextcloud Server is upgraded to 31.0.1.
It is recommended that the Nextcloud Enterprise Server is upgraded to 31.0.1.
Workarounds
References
For more information
If you have any questions or comments about this advisory: