CVE-2017-0885

Publication date

2017-04-05 20:00:00

Family

hackerone

State

PUBLISHED

Description

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and subfolders by comparing the exception messages.