Nextcloud Server before 11.0.7 and 12.0.5 suffers from an Authorization Bypass Through User-Controlled Key vulnerability. A missing ownership check allowed logged-in users to change the scope of app passwords of other users. Note that the app passwords themselves where neither disclosed nor could the error be misused to identify as another user.
References
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: hackerone

Published: 2018-02-07T00:00:00

Updated: 2018-03-28T19:57:01

Reserved: 2016-11-30T00:00:00


Link: CVE-2017-0936

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-03-28T20:29:00.270

Modified: 2019-10-09T23:21:14.523


Link: CVE-2017-0936

JSON object: View

cve-icon Redhat Information

No data.

CWE