Learn about CVE-2017-0884 affecting Nextcloud Server versions before 9.0.55 and 10.0.2. Find out how authenticated attackers can create folders in read-only directories and steps to mitigate the issue.
Nextcloud Server versions prior to 9.0.55 and 10.0.2 have a vulnerability that allows the creation of folders in read-only directories, even without proper permissions. This flaw in the file caching system enables an authenticated attacker to generate empty folders within a shared folder.
Understanding CVE-2017-0884
This CVE affects Nextcloud Server versions before 9.0.55 and 10.0.2, allowing unauthorized creation of folders in read-only directories.
What is CVE-2017-0884?
The vulnerability in Nextcloud Server versions prior to 9.0.55 and 10.0.2 permits the creation of folders in read-only directories by authenticated attackers, exploiting a flaw in the file caching system.
The Impact of CVE-2017-0884
Technical Details of CVE-2017-0884
Nextcloud Server vulnerability details and affected systems.
Vulnerability Description
The flaw allows the creation of folders in read-only directories by exploiting a logical error in the file caching layer.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2017-0884.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates