Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-1246 Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs a strict Content-Security-Policy preventing exploitation of this XSS issue on modern web browsers.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: hackerone

Published:

Updated: 2024-08-05T13:18:06.510Z

Reserved: 2016-11-30T00:00:00

Link: CVE-2017-0893

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-05-08T20:29:00.287

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-0893

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses