Nextcloud Server before 9.0.55 and 10.0.2 suffers from a...
Moderate severity
Unreviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Apr 20, 2025
Description
Published by the National Vulnerability Database
Apr 5, 2017
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Apr 20, 2025
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a bypass in the quota limitation. Due to not properly sanitizing values provided by the
OC-Total-Length
HTTP header an authenticated adversary may be able to exceed their configured user quota. Thus using more space than allowed by the administrator.References