Security: nextcloud/security-advisories
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Audit log is not properly logging unsetting of share expiration dateGHSA-fxpq-wq7c-vppf published
Jul 12, 2021 by LukasReschkeLow -
Filenames not escaped by default in controllers using DownloadResponseGHSA-3hjp-26x8-mhf6 published
Jul 12, 2021 by LukasReschkeLow -
Ratelimit not applied on OCS API responsesGHSA-48rx-3gmf-g74j published
Jul 12, 2021 by LukasReschkeLow -
Sensitive data may not be removed from storage on account removalGHSA-g5gf-rmhm-wpxw published
Jun 8, 2021 by LukasReschkeLow -
Malicious user could break user administration pageGHSA-fx62-q47f-f665 published
Jun 1, 2021 by LukasReschkeLow -
Trusted servers exchange can be triggered by attackerGHSA-j875-vr2q-h6x6 published
Jun 1, 2021 by LukasReschkeModerate -
Session Fixation in Nextcloud TalkGHSA-p6h7-84v4-827r published
Jun 15, 2021 by LukasReschkeLow -
Nextcloud deck sharee search leaks searches to lookupserver by defaultGHSA-h8f6-wg82-6p7r published
Jun 1, 2021 by LukasReschkeLow -
Default Nextcloud Server and iOS Client leak sharee searches to NextcloudGHSA-m7w4-cvjr-76mh published
Jun 1, 2021 by LukasReschkeLow -
Files Drop public link can be added as federated shareGHSA-grph-cm44-p3jv published
Jun 1, 2021 by LukasReschkeLow