Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published: 2018-03-28T20:00:00Z

Updated: 2024-09-16T21:58:27.852Z

Reserved: 2016-11-30T00:00:00

Link: CVE-2017-0936

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-03-28T20:29:00.270

Modified: 2019-10-09T23:21:14.523

Link: CVE-2017-0936

cve-icon Redhat

No data.