CVE-2017-9286
nextcloud package security issues with /srv/www/htdocs
Severity Score
8.8
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
El paquete de NextCloud en openSUSE empleaba /srv/www/htdocs de forma no segura, lo que podría haber permitido que los scripts ejecutándose como usuario wwwrun escalasen privilegios a root durante la actualización del paquete NextCloud.
*Credits:
Ludwig Nussel of SUSE
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2017-05-29 CVE Reserved
- 2018-03-01 CVE Published
- 2023-11-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://bugzilla.suse.com/show_bug.cgi?id=1036756 | X_refsource_confirm | |
https://www.suse.com/de-de/security/cve/CVE-2017-9286 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://lists.opensuse.org/opensuse-updates/2017-10/msg00010.html | 2023-11-07 |