CVE-2017-0887

MEDIUM

Nextcloud Server <9.0.55,10.0.2 - Auth Bypass

Title source: llm

Description

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

Scores

CVSS v3 4.3
EPSS 0.0025
EPSS Percentile 47.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Classification

CWE
CWE-807 CWE-20
Status published

Affected Products (2)

nextcloud/nextcloud_server < 9.0.55
Nextcloud/Nextcloud Server < All versions before 9.0.55 and 10.0.2

Timeline

Published Apr 05, 2017
Tracked Since Feb 18, 2026