Bugzilla – Bug 1105599
VUL-0: CVE-2018-3776: nextcloud: Improper input validation allows attackers to not have their actions logged to the audit log
Last modified: 2018-08-22 10:09:41 UTC
rh#1619895 Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. References: https://bugzilla.redhat.com/show_bug.cgi?id=1619895 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3776 http://www.cvedetails.com/cve/CVE-2018-3776/ https://hackerone.com/reports/232347 https://nextcloud.com/security/advisory/?id=NC-SA-2018-006
nextcloud is in official repos for Leap 42.3, 15.0 Tumbleweed, SLE-15 und SLE-12-SP3 only avaible in 13.0.4 and 13.0.5.
Already fixed in 42.3.