CVE-2018-3762
openSUSE Security Advisory - openSUSE-SU-2018:1924-1
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
Nextcloud Server en versiones anteriores a la 12.0.8 y la 13.0.3 sufre de comprobaciones incorrectas de permisos abandonados para comparticiones entrantes, lo que permite que un usuario pueda seguir solicitando previsualizaciones de archivos a los que no deberÃa tener acceso.
An update that fixes two vulnerabilities is now available. This update for nextcloud fixes the following issues. Fixed improper authentication on the OAuth2 token endpoint. Fixed improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-12-28 CVE Reserved
- 2018-07-05 CVE Published
- 2024-08-05 CVE Updated
- 2025-08-05 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-281: Improper Preservation of Permissions
- CWE-284: Improper Access Control
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://hackerone.com/reports/358339 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://nextcloud.com/security/advisory/?id=nc-sa-2018-002 | 2023-02-28 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | < 12.0.8 Search vendor "Nextcloud" for product "Nextcloud Server" and version " < 12.0.8" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Nextcloud Server Search vendor "Nextcloud" for product "Nextcloud Server" | >= 13.0.0 < 13.0.3 Search vendor "Nextcloud" for product "Nextcloud Server" and version " >= 13.0.0 < 13.0.3" | - |
Affected
|