XSS in SVG images when opened outside of Nextcloud
Package
Server
(Nextcloud)
Affected versions
>= 31.0.0, >= 32.0.0
Patched versions
31.0.12, 32.0.3
Server
(Nextcloud Entreprise)
>= 31.0.0, >= 32.0.0
31.0.12, 32.0.3
Impact
A missing sanitization allowed malicious users to circumvent the content security policy when a malicious user manages to trick a user it viewing an uploaded SVG outside of the Nextcloud Servers web page.
Patches
It is recommended that the Nextcloud Server is upgraded to 31.0.12 or 32.0.3
It is recommended that the Nextcloud Enterprise Server is upgraded to 31.0.12 or 32.0.3
Workarounds
References
For more information
If you have any questions or comments about this advisory: