← Back to CVE List

CVE-2017-0883

Published: 2017-04-05T20:59Z
Last Modified: 2024-11-21T03:03Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission set. This may allow an attacker to edit files in a share despite having only a 'read' permission set. Note that this only affects folders and files that the adversary has at least read-only permissions for. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt