CVE-2018-16466

Improper revalidation of permissions in Nextcloud Server prior to 14.0.0, 13.0.6 and 12.0.11 lead to not accepting access restrictions by acess tokens.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.1 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
hackeroneCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
VendorProductVersion
nextcloudnextcloud_server
𝑥
< 12.0.11
nextcloudnextcloud_server
13.0.0 ≤
𝑥
< 13.0.6
nextcloudnextcloud_server
14.0.0:beta1
nextcloudnextcloud_server
14.0.0:beta2
nextcloudnextcloud_server
14.0.0:beta3
nextcloudnextcloud_server
14.0.0:beta4
nextcloudnextcloud_server
14.0.0:rc1
nextcloudnextcloud_server
14.0.0:rc2
𝑥
= Vulnerable software versions