MGASA-2018-0394 - Updated nextcloud packages fix security vulnerability

Publication date: 14 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0394.html
Type: security
Affected Mageia releases: 6
CVE: CVE-2018-3780

Nextcloud has been updated to 13.0.6 and fixes atleast the following
security issue:

A missing sanitization of search results for an autocomplete field could
lead to a stored XSS requiring user-interaction. The missing sanitization
only affected user names, hence malicious search results could only be
crafted by authenticated users (CVE-2018-3780).

References:
- https://bugs.mageia.org/show_bug.cgi?id=23497
- https://nextcloud.com/changelog/#latest13
- - - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3780

SRPMS:
- 6/core/nextcloud-13.0.6-1.mga6

Mageia 2018-0394: nextcloud security update

Nextcloud has been updated to 13.0.6 and fixes atleast the following security issue: A missing sanitization of search results for an autocomplete field could lead to a stored XSS ...

Summary

Nextcloud has been updated to 13.0.6 and fixes atleast the following security issue:
A missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users (CVE-2018-3780).

References

- https://bugs.mageia.org/show_bug.cgi?id=23497

- https://nextcloud.com/changelog/#latest13

- - - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3780

Resolution

MGASA-2018-0394 - Updated nextcloud packages fix security vulnerability

SRPMS

- 6/core/nextcloud-13.0.6-1.mga6

Severity
Publication date: 14 Oct 2018
URL: https://advisories.mageia.org/MGASA-2018-0394.html
Type: security
CVE: CVE-2018-3780

Related News