« Volver al listado

CVE-2018-16463

Estado: ModificadaBaja (3.1)—

A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-16463",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:S/C:P/I:P/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.5,
        "exploitabilityScore": 0.5
      }
    ]
  },
  "affected": [
    {
      "source": "support@hackerone.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Nextcloud Server",
          "versions": [
            {
              "status": "affected",
              "version": "<14.0.0, <13.0.3, <12.0.8"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-10-30T21:29:00.510",
  "references": [
    {
      "url": "https://hackerone.com/reports/237184",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://nextcloud.com/security/advisory/?id=NC-SA-2018-013",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "support@hackerone.com"
    },
    {
      "url": "https://hackerone.com/reports/237184",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://nextcloud.com/security/advisory/?id=NC-SA-2018-013",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "support@hackerone.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-384"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-384"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A bug causing session fixation in Nextcloud Server prior to 14.0.0, 13.0.3 and 12.0.8 could potentially allow an attacker to obtain access to password protected shares."
    },
    {
      "lang": "es",
      "value": "Un error que provoca una fijación de sesión en Nextcloud Server en versiones anteriores a 14.0.0, 13.0.3 y 12.0.8 podría permitir que un atacante obtenga acceso a comparticiones protegidas por contraseña."
    }
  ],
  "lastModified": "2026-06-17T01:44:20.150",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8CEE07AB-CFB8-41CB-85E7-06FF3977DD2B",
              "versionEndExcluding": "12.0.8"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4C66EEA7-59A5-4F3B-ADC3-5A7422B1FBC0",
              "versionEndExcluding": "13.0.3",
              "versionStartIncluding": "13.0.0"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:14.0.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A52F8C90-1506-454B-A77F-BE151363DFD4"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:14.0.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "813FFC04-945F-4710-9474-344CDFE60536"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:14.0.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0E6E366E-B480-4F56-8921-41B3AD1D2C3E"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:14.0.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6472CDD2-0FA2-4742-82DE-7F5DA877D55A"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:14.0.0:rc1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9C1757C-A694-4F22-AF99-3FDC11E7BC8E"
            },
            {
              "criteria": "cpe:2.3:a:nextcloud:nextcloud_server:14.0.0:rc2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9F1B3B90-A91E-4285-93BF-30A5CE9C1AB7"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "support@hackerone.com"
}