Workflows do not require password confirmation on API level
Package
Server
(Nextcloud)
Affected versions
>= 26.0.0, >= 27.0.0
Patched versions
26.0.9, 27.1.4
Server
(Nextcloud Enterprise)
>= 23.0.0, >= 24.0.0, >= 25.0.0, >= 26.0.0, >= 27.0.0
23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, 27.1.4
Impact
When an attacker manages to get access to an active session of another user via another way, they could delete and modify workflows by sending calls directly to the API bypassing the password confirmation shown in the UI.
Patches
It is recommended that the Nextcloud Server is upgraded to 26.0.9 or 27.1.4
It is recommended that the Nextcloud Enterprise Server is upgraded to 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9 or 27.1.4
Workarounds
References
For more information
If you have any questions or comments about this advisory: