The packaging of NextCloud in openSUSE used /srv/www/htdocs in an unsafe manner, which could have allowed scripts running as wwwrun user to escalate privileges to root during nextcloud package upgrade.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Leap | Opensuse | 42.3 (including) | 42.3 (including) |