CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
AI Score
Confidence
High
EPSS
Percentile
21.4%
When an attacker manages to get access to an active session of another user via another way, they could delete and modify workflows by sending calls directly to the API bypassing the password confirmation shown in the UI.
It is recommended that the Nextcloud Server is upgraded to 26.0.9 or 27.1.4
It is recommended that the Nextcloud Enterprise Server is upgraded to 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9 or 27.1.4
If you have any questions or comments about this advisory:
CVSS3
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
AI Score
Confidence
High
EPSS
Percentile
21.4%