Bugzilla – Full Text Bug Listing |
Summary: | VUL-1: CVE-2019-15621: nextcloud: Improper permissions preservation causes sharees to be able to reshare with write permissions when sharing the mount point of a share they received, as a public link | ||
---|---|---|---|
Product: | [openSUSE] openSUSE Distribution | Reporter: | Robert Frohl <rfrohl> |
Component: | Security | Assignee: | Eric Schirra <ecsos> |
Status: | RESOLVED FIXED | QA Contact: | Security Team bot <security-team> |
Severity: | Minor | ||
Priority: | P4 - Low | ||
Version: | Leap 15.1 | ||
Target Milestone: | --- | ||
Hardware: | Other | ||
OS: | Other | ||
URL: | https://smash.suse.de/issue/252412/ | ||
Whiteboard: | |||
Found By: | Security Response Team | Services Priority: | |
Business Priority: | Blocker: | --- | |
Marketing QA Status: | --- | IT Deployment: | --- |
Description
Robert Frohl
2020-02-05 09:42:06 UTC
not yet fixed in Leap 15.1 and 15.2 What have this todo with Leap? Leap have another branch. (In reply to Eric Schirra from comment #2) > What have this todo with Leap? > Leap have another branch. advisory states affected software: Nextcloud Server < 16.0.2 Nextcloud Server < 15.0.9 Nextcloud Server < 14.0.13 Leap is on 15.0.7. This is an autogenerated message for OBS integration: This bug (1162784) was mentioned in https://build.opensuse.org/request/show/770689 15.1 / nextcloud https://build.opensuse.org/request/show/770691 Backports:SLE-15-SP1 / nextcloud openSUSE-SU-2020:0220-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 1162766,1162775,1162776,1162781,1162782,1162784 CVE References: CVE-2019-15613,CVE-2019-15621,CVE-2019-15623,CVE-2019-15624,CVE-2020-8118,CVE-2020-8119 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): nextcloud-13.0.12-19.1 openSUSE-SU-2020:0220-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 1162766,1162775,1162776,1162781,1162782,1162784 CVE References: CVE-2019-15613,CVE-2019-15621,CVE-2019-15623,CVE-2019-15624,CVE-2020-8118,CVE-2020-8119 Sources used: openSUSE Leap 15.1 (src): nextcloud-15.0.14-lp151.2.3.1 openSUSE Backports SLE-15-SP1 (src): nextcloud-15.0.14-bp151.3.3.1 openSUSE Backports SLE-15 (src): nextcloud-13.0.12-bp150.19.1 SUSE Package Hub for SUSE Linux Enterprise 12 (src): nextcloud-13.0.12-19.1 openSUSE-SU-2020:0229-1: An update that fixes 6 vulnerabilities is now available. Category: security (moderate) Bug References: 1162766,1162775,1162776,1162781,1162782,1162784 CVE References: CVE-2019-15613,CVE-2019-15621,CVE-2019-15623,CVE-2019-15624,CVE-2020-8118,CVE-2020-8119 Sources used: openSUSE Backports SLE-15-SP1 (src): nextcloud-15.0.14-bp151.3.6.1 Leap is now 15.0.14. Think we can close it. |