Security: nextcloud/security-advisories
Security Advisories
View information about security vulnerabilities from this repository's maintainers.
-
OAuth2 client secrets were stored in a recoverable wayGHSA-fvpc-8hq6-jgq2 published
Nov 15, 2024 by nickvergessenLow -
Missing password confirmation when changing external storage optionsGHSA-vrhf-532w-99rg published
Nov 15, 2024 by nickvergessenModerate -
Global credentials of external storages are sent back to the frontendGHSA-x9q3-c7f8-3rcg published
Nov 15, 2024 by nickvergessenModerate -
Shares are not removed when user is limited to share with in their groups and being removed from one of themGHSA-35gc-jc6x-29cm published
Nov 15, 2024 by nickvergessenLow -
Incomplete sanitization of SVG files allows to embed other images into previewsGHSA-5m5g-hw8c-2236 published
Nov 15, 2024 by nickvergessenModerate -
User can copy folder that contain files that are blocked by the files access controlGHSA-g8pr-g25r-58xj published
Nov 15, 2024 by nickvergessenModerate -
Attachments folder for Text app is accessible on "Files drop" and "Password protected" sharesGHSA-gxph-5m4j-pfmj published
Nov 15, 2024 by nickvergessenLow -
Open redirection when logging in with User OIDCGHSA-784j-x2g5-4g7q published
Nov 15, 2024 by nickvergessenLow -
Authorization Bypass Through User-Controlled Key in TablesGHSA-4qqp-9h2g-7qg7 published
Nov 15, 2024 by nickvergessenModerate -
Share information of Tables app is not limited to affected usersGHSA-rgvc-xr2w-qq45 published
Nov 15, 2024 by nickvergessenLow