Catégorie : sécurité

httpoxy Can Affect Nextcloud, Get Your Update Now

We ship Guzzle 5 as part of Nextcloud. This handles http requests and supports HTTP_PROXY environment variable which can be abused, in some special scenario’s, by an attacker to read content. In the worst case, when you use the ajax cron feature, an attacker can…

Read more
HackerOne

Introducing the Nextcloud bug bounty program

Today we are happy to announce the Nextcloud bug bounty program. We offer some of the highest bounties in the open source software industry, rewarding responsible disclosure with up to $5,000 for qualifying vulnerabilities! We have partnered with the HackerOne platform because of its extraordinary…

Read more