Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are...
Vulnerability Description
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-9461
Credits & Attribution
No credits recorded in the NVD database.
References
- https://owncloud.org/security/advisory/?id=oc-sa-2016-014
- https://nextcloud.com/security/advisory/?id=nc-sa-2016-004
- http://www.securityfocus.com/bid/97276
- https://github.com/owncloud/core/commit/acbbadb71ceee7f01da347f7dcd519beda78cc47
- https://github.com/owncloud/core/commit/c0a4b7b3f38ad2eaf506484b3b92ec678cb021c9
- https://github.com/owncloud/core/commit/121a3304a0c37ccda0e1b63ddc528cba9121a36e
- https://github.com/owncloud/core/commit/0622e635d97cb17c5e1363e370bb8268cc3d2547
- https://hackerone.com/reports/145950
- https://github.com/nextcloud/server/commit/3491400261c1454a9a30d3ec96969573330120cc
More from n/a
View All →Affected Vendor
Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.