Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
Advisories
Source ID Title
EUVD EUVD EUVD-2016-10267 Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated attacker with access to a read-only share to put new files in there. It was not possible to modify existing files.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-06T02:50:38.345Z

Reserved: 2016-11-19T00:00:00

Link: CVE-2016-9461

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-03-28T02:59:00.840

Modified: 2025-04-20T01:37:25.860

Link: CVE-2016-9461

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.