Loading HuntDB...

Expired reshare links allow access to all files in share

Critical
N
Nextcloud
Submitted None

Team Summary

Official summary from Nextcloud

After a reshared subfolder link has expired, the link allows access to the full folder. I found the Problem in Nextcloud 14.0.3, but it still persists in 14.0.4 Steps: 1. share folder "A" with an nextcloud group 2. reshare a subfolder "B" of this folder with another user on this group (in this case the user both have group admin) as public link. 3. set an expiry date 4. let date expire 5. open link Expected result: You see a message that the link has expired Actual result: You have access to the initial shared folder "A" Impact After getting a reshared link for a subfolder with expiry date (legitimately or through social engineering) the attacker just has to wait for expiry for full access to all Files in the share.

Reported by frr

Report Details

Additional information and metadata

State

Closed

Substate

Resolved

Submitted

Weakness

Improper Access Control - Generic