CVE-2017-0887

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/04/2017
Last modified:
20/04/2025

Description

Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the `OC-Total-Length` HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 9.0.55 (excluding)
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 10.0.0 (including) 10.0.2 (excluding)