CVE-2016-9464
Summary
| CVE | CVE-2016-9464 |
|---|---|
| State | PUBLISHED |
| Assigner | hackerone |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-03-28 02:59:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users should be able to unshare the file to themselves but not to the whole group. The previous API implementation simply unshared the file to all users in the group. |
Risk And Classification
Primary CVSS: v3.0 4.3 MEDIUM from [email protected]
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Problem Types: CWE-285 | CWE-285 Improper Authorization (CWE-285)
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 4.3 | MEDIUM | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
| 2.0 | [email protected] | Primary | 4 | AV:N/AC:L/Au:S/C:N/I:P/A:N |
CVSS v3.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
LowUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
SingleConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:L/Au:S/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nextcloud | Nextcloud Server | All | All | All | All |
| Application | Nextcloud | Nextcloud Server | 10.0 | rc1 | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | Nextcloud Server Nextcloud Server Before 9.0.54 And 10.0.0 | affected Nextcloud Server Nextcloud Server before 9.0.54 and 10.0.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Nextcloud CVE-2016-9464 Unauthorized Access Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| advisory – Nextcloud | af854a3a-2127-422b-91ae-364da2661108 | nextcloud.com | Patch, Vendor Advisory |
| Do not allow to delete/update group shares as a group member · nextcloud/server@7289cb5 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Issue Tracking, Patch, Third Party Advisory |
| Do not allow to delete/update group shares as a group member · nextcloud/server@a5471b4 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Issue Tracking, Patch, Third Party Advisory |
| HackerOne | af854a3a-2127-422b-91ae-364da2661108 | hackerone.com | Exploit, Third Party Advisory |
| Add intergration test · nextcloud/server@e2c4f4f · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Issue Tracking, Patch, Third Party Advisory |
| Add intergration test · nextcloud/server@3387e5d · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Issue Tracking, Patch, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.