Lucene search

K
hackeroneKichernde_erbseH1:1652903
HistoryJul 28, 2022 - 2:40 p.m.

Nextcloud: Exception logging in Sharepoint app reveals clear-text connection details

2022-07-2814:40:07
kichernde_erbse
hackerone.com
5

0.001 Low

EPSS

Percentile

46.9%

Summary:

On Exceptions thrown in the context of the SharePoint app, connection credentials may be written to the Nextcloud log in clear text.

Steps To Reproduce:

Attempt to configure a sharepoint mount in an erroneous way.

Supporting Material/References:

Impact

When an attacker gets hold of the nextcloud log, they may gain knowledge of credentials to connect to a SharePoint service.

0.001 Low

EPSS

Percentile

46.9%