CVE Vulnerabilities

CVE-2022-36075

Improper Privilege Management

Published: Sep 15, 2022 | Modified: Sep 19, 2022
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or 1.14.1. There are no known workarounds for this issue

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Files_access_control Nextcloud * 1.12.2 (excluding)
Files_access_control Nextcloud 1.13.0 (including) 1.13.0 (including)
Files_access_control Nextcloud 1.14.0 (including) 1.14.0 (including)

Potential Mitigations

References