Description
Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests with access to the collective were able to access the deleted pages directly from the trashbin. This issue has been patched in version 4.3.0.
Problem types
CWE-284: Improper Access Control
Product status
References
github.com/...sories/security/advisories/GHSA-8mpv-ggq8-hf3w
github.com/nextcloud/collectives/pull/2432