CVE-2018-16466Improper Access Control in Server

Severity
8.1HIGHNVD
EPSS
0.1%
top 68.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedOct 30
Latest updateMay 13

Description

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 2.8 | Impact: 5.2

Affected Packages2 packages

NVDnextcloud/nextcloud_server13.0.013.0.6+2
CVEListV5nextcloud/nextcloud_server<14.0.0, <13.0.6, <12.0.11

🔴Vulnerability Details

2
GHSA
GHSA-6mm6-pp6h-9p36: Improper revalidation of permissions in Nextcloud Server prior to 142022-05-13
CVEList
CVE-2018-16466: Improper revalidation of permissions in Nextcloud Server prior to 142018-10-30

💬Community

3
Bugzilla
CVE-2018-16466 nextcloud: Improper validation of permissions2018-11-05
Bugzilla
CVE-2018-16466 nextcloud: Improper validation of permissions [fedora-all]2018-11-05
Bugzilla
CVE-2018-16466 nextcloud: Improper validation of permissions [epel-7]2018-11-05
CVE-2018-16466 — Improper Access Control in Server | cvebase