Security: nextcloud/security-advisories
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
Attacker can obtain write access to any federated share/public linkGHSA-jf9h-v24c-22g5 published
Jun 1, 2021 by LukasReschkeHigh -
Default settings leak federated cloud ID to lookup server of all usersGHSA-396j-vqpr-qg45 published
Jun 1, 2021 by LukasReschkeLow -
End to end encryption folder locking is not properly protectedGHSA-3829-45wm-ww36 published
Jun 1, 2021 by LukasReschkeLow -
Missing permission check on email metadata retrievalGHSA-mxx2-6rg9-v2vc published
Jun 1, 2021 by LukasReschkeHigh -
Default Nextcloud Server and Android Client leak sharee searches to NextcloudGHSA-22v9-q3r6-x7cj published
Jun 1, 2021 by LukasReschkeLow -
SSL certificate was not validated in Provider Registration FlowGHSA-qpgp-vf4p-wcw5 published
Jun 1, 2021 by LukasReschkeModerate -
Alias creation did not validate account IDGHSA-jmgp-77jq-fjp3 published
May 31, 2021 by LukasReschkeLow -
Ratelimiting can be bypassed using IPv6 subnetsGHSA-2967-6mrp-gg3p published
Jun 1, 2021 by LukasReschkeLow