Expired reshare links allow access to all files in share
Team Summary
Official summary from Nextcloud
After a reshared subfolder link has expired, the link allows access to the full folder. I found the Problem in Nextcloud 14.0.3, but it still persists in 14.0.4 Steps: 1. share folder "A" with an nextcloud group 2. reshare a subfolder "B" of this folder with another user on this group (in this case the user both have group admin) as public link. 3. set an expiry date 4. let date expire 5. open link Expected result: You see a message that the link has expired Actual result: You have access to the initial shared folder "A" Impact After getting a reshared link for a subfolder with expiry date (legitimately or through social engineering) the attacker just has to wait for expiry for full access to all Files in the share.
Report Details
Additional information and metadata
State
Closed
Substate
Resolved
Submitted
Weakness
Improper Access Control - Generic