Can download files by zipping the folder
Medium
N
Nextcloud
Submitted None
Team Summary
Official summary from Nextcloud
Security advisory at https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vhj3-mch4-67fq
Actions:
Reported by
nickvergessen
Vulnerability Details
Technical details and impact analysis
1. Create folder and share it as view-only
{F2846936}
2. Access this folder with Testuser
{F2846943}
3. Go one level up and compress the whole folder
{F2846942}
4. The zip file can be downloaded and extracted locally
{F2846939}
{F2846941}
5. The folder itself can not be downloaded directly
{F2846937}
## Impact
Can download files without download permissions
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic