Bug 1105599 - (CVE-2018-3776) VUL-0: CVE-2018-3776: nextcloud: Improper input validation allows attackers to not have their actions logged to the audit log
(CVE-2018-3776)
VUL-0: CVE-2018-3776: nextcloud: Improper input validation allows attackers t...
Status: RESOLVED WORKSFORME
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.0
Other Other
: P5 - None : Normal (vote)
: ---
Assigned To: Eric Schirra
Security Team bot
https://smash.suse.de/issue/212642/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2018-08-22 07:16 UTC by Alexander Bergmann
Modified: 2018-08-22 10:09 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2018-08-22 07:16:54 UTC
rh#1619895

Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could
lead to an attacker's actions not being logged in the audit log.

References:
https://bugzilla.redhat.com/show_bug.cgi?id=1619895
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3776
http://www.cvedetails.com/cve/CVE-2018-3776/
https://hackerone.com/reports/232347
https://nextcloud.com/security/advisory/?id=NC-SA-2018-006
Comment 1 Eric Schirra 2018-08-22 08:32:54 UTC
nextcloud is in official repos for Leap 42.3, 15.0 Tumbleweed, SLE-15 und SLE-12-SP3 only avaible in 13.0.4 and 13.0.5.
Comment 2 Andreas Stieger 2018-08-22 10:09:41 UTC
Already fixed in 42.3.