Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the ninja-forms domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /var/www/html/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the simple-custom-post-order domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /var/www/html/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the wp-mail-logging domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /var/www/html/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the health-check domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /var/www/html/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the updraftplus domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /var/www/html/wp-includes/functions.php on line 6114

Notice: Function _load_textdomain_just_in_time was called incorrectly. Translation loading for the rocket domain was triggered too early. This is usually an indicator for some code in the plugin or theme running too early. Translations should be loaded at the init action or later. Please see Debugging in WordPress for more information. (This message was added in version 6.7.0.) in /var/www/html/wp-includes/functions.php on line 6114
{"id":2255,"date":"2022-04-05T13:44:15","date_gmt":"2022-04-05T13:44:15","guid":{"rendered":"https:\/\/web2.nextcloud.com\/?page_id=2255"},"modified":"2023-01-24T12:53:44","modified_gmt":"2023-01-24T11:53:44","slug":"security","status":"publish","type":"page","link":"https:\/\/staging.nextcloud.com\/fr\/security\/","title":{"rendered":"Security"},"content":{"rendered":"

[vc_section el_class=\u00a0\u00bbtitlebar press_releases_titlebar\u00a0\u00bb css=\u00a0\u00bb.vc_custom_1667984996569{background-image: url(https:\/\/nextcloud.com\/wp-content\/uploads\/2022\/11\/nextcloud-security-advisories-titlebar.jpg?id=60592) !important;}\u00a0\u00bb][vc_row content_placement=\u00a0\u00bbmiddle\u00a0\u00bb][vc_column width=\u00a0\u00bb1\/2″ el_class=\u00a0\u00bbcenterMobile\u00a0\u00bb][vc_column_text el_class=\u00a0\u00bbpage-title\u00a0\u00bb]<\/p>\n

Security and advisories<\/h1>\n

[\/vc_column_text][vc_column_text el_class=\u00a0\u00bbpage-subtitle\u00a0\u00bb]This page hosts our security policies and information with regards to reporting security flaws.[\/vc_column_text][\/vc_column][vc_column width=\u00a0\u00bb1\/2″][\/vc_column][\/vc_row][\/vc_section][vc_section el_id=\u00a0\u00bbcompliant_by_design_section\u00a0\u00bb el_class=\u00a0\u00bbcompliant_by_design_section nc_default_section\u00a0\u00bb css=\u00a0\u00bb.vc_custom_1667808786077{margin-bottom: 0px !important;}\u00a0\u00bb][vc_row gap=\u00a0\u00bb30″ content_placement=\u00a0\u00bbmiddle\u00a0\u00bb][vc_column width=\u00a0\u00bb1\/2″ el_class=\u00a0\u00bbcenterMobile\u00a0\u00bb][vc_column_text el_class=\u00a0\u00bbnc_text_as_separator\u00a0\u00bb]Nextcloud security[\/vc_column_text][vc_column_text]<\/p>\n

Security in Nextcloud<\/h2>\n

[\/vc_column_text][vc_column_text css=\u00a0\u00bb.vc_custom_1668155545215{margin-top: 1.5rem !important;margin-bottom: 1.5rem !important;}\u00a0\u00bb]Nextcloud is designed to offer the best security in the on-premises content collaboration industry. Read more about the security features and our development process.[\/vc_column_text][vc_btn title=\u00a0\u00bbMore about security\u00a0\u00bb link=\u00a0\u00bburl:%2Fsecure%2F|title:More%20about%20security\u00a0\u00bb el_class=\u00a0\u00bbbtn-main\u00a0\u00bb][\/vc_column][vc_column width=\u00a0\u00bb1\/2″][vc_row_inner gap=\u00a0\u00bb15″ el_class=\u00a0\u00bbcompliant_iconboxes\u00a0\u00bb][vc_column_inner]

<\/i><\/div>\n\t
\n\t

Server owners<\/h4>
For server owners, our documentation has a section with best practices and tips on securing a Nextcloud server.<\/div>Voir plus <\/i><\/span><\/div><\/div><\/a><\/div>[\/vc_column_inner][\/vc_row_inner][\/vc_column][vc_column el_class=\u00a0\u00bbbtns-inline-centered\u00a0\u00bb][vc_btn title=\u00a0\u00bbSecurity advisories\u00a0\u00bb align=\u00a0\u00bbcenter\u00a0\u00bb i_icon_fontawesome=\u00a0\u00bbfas fa-external-link-alt\u00a0\u00bb add_icon=\u00a0\u00bbtrue\u00a0\u00bb link=\u00a0\u00bburl:https%3A%2F%2Fgithub.com%2Fnextcloud%2Fsecurity-advisories%2Fsecurity%2Fadvisories|title:Security%20advisories|target:_blank\u00a0\u00bb el_class=\u00a0\u00bbbtn-main\u00a0\u00bb][vc_btn title=\u00a0\u00bbOfficial CVE database\u00a0\u00bb align=\u00a0\u00bbcenter\u00a0\u00bb i_icon_fontawesome=\u00a0\u00bbfas fa-external-link-alt\u00a0\u00bb add_icon=\u00a0\u00bbtrue\u00a0\u00bb link=\u00a0\u00bburl:https%3A%2F%2Fwww.cvedetails.com%2Fvendor%2F15913%2FNextcloud.html|title:See%20a%20full%20list%20of%20historic%20advisories%20in%20the%20CVE%20database.|target:_blank\u00a0\u00bb el_class=\u00a0\u00bbbtn-main\u00a0\u00bb][vc_btn title=\u00a0\u00bbThreat model\u00a0\u00bb align=\u00a0\u00bbcenter\u00a0\u00bb link=\u00a0\u00bburl:%2Fsecurity%2Fthreat-model|title:Threat%20model\u00a0\u00bb el_class=\u00a0\u00bbbtn-main\u00a0\u00bb][\/vc_column][\/vc_row][\/vc_section][vc_section el_class=\u00a0\u00bbnc_default_section\u00a0\u00bb el_id=\u00a0\u00bbpress-2022″ css=\u00a0\u00bb.vc_custom_1667808823923{margin-top: 0px !important;}\u00a0\u00bb][vc_row][vc_column][vc_column_text css=\u00a0\u00bb.vc_custom_1668079566982{margin-bottom: 2rem !important;}\u00a0\u00bb]<\/p>\n

Report
\na security issue<\/h2>\n

[\/vc_column_text][vc_separator color=\u00a0\u00bbcustom\u00a0\u00bb border_width=\u00a0\u00bb2″ el_width=\u00a0\u00bb20″ accent_color=\u00a0\u00bb#0082c9″ el_class=\u00a0\u00bbnc_separator_line\u00a0\u00bb][vc_column_text css=\u00a0\u00bb.vc_custom_1667986091963{margin-bottom: 2rem !important;}\u00a0\u00bb]<\/p>\n

If you have discovered a security issue with Nextcloud, please read our responsible
\ndisclosure guidelines and contact us at\u00a0
hackerone.com\/nextcloud<\/strong><\/a>.
\nYour report should include:[\/vc_column_text][vc_row_inner gap=\u00a0\u00bb25″ el_class=\u00a0\u00bbiconboxes\u00a0\u00bb][vc_column_inner el_class=\u00a0\u00bbiconbox\u00a0\u00bb width=\u00a0\u00bb1\/3″][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-hashtag\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb align=\u00a0\u00bbcenter\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text el_class=\u00a0\u00bbiconbox_title\u00a0\u00bb]<\/p>\n

Product version<\/h4>\n

[\/vc_column_text][\/vc_column_inner][vc_column_inner el_class=\u00a0\u00bbiconbox\u00a0\u00bb width=\u00a0\u00bb1\/3″][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-align-left\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb align=\u00a0\u00bbcenter\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text el_class=\u00a0\u00bbiconbox_title\u00a0\u00bb]<\/p>\n

A\u00a0vulnerability description<\/h4>\n

[\/vc_column_text][\/vc_column_inner][vc_column_inner el_class=\u00a0\u00bbiconbox\u00a0\u00bb width=\u00a0\u00bb1\/3″][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-list-ol\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb align=\u00a0\u00bbcenter\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text el_class=\u00a0\u00bbiconbox_title\u00a0\u00bb]<\/p>\n

Reproduction steps<\/h4>\n

[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][vc_row css=\u00a0\u00bb.vc_custom_1667985711800{margin-top: 3rem !important;}\u00a0\u00bb][vc_column][vc_column_text]<\/p>\n

What happens next<\/h3>\n

[\/vc_column_text][vc_row_inner equal_height=\u00a0\u00bbyes\u00a0\u00bb gap=\u00a0\u00bb20″ el_class=\u00a0\u00bbiconboxes\u00a0\u00bb css=\u00a0\u00bb.vc_custom_1667986169446{margin-top: 2rem !important;}\u00a0\u00bb][vc_column_inner el_class=\u00a0\u00bbiconbox\u00a0\u00bb width=\u00a0\u00bb1\/4″][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-check-circle\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text]A member of the security team will confirm the vulnerability, determine its impact, and develop a fix.[\/vc_column_text][\/vc_column_inner][vc_column_inner el_class=\u00a0\u00bbiconbox\u00a0\u00bb width=\u00a0\u00bb1\/4″][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-code-branch\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text]The fix will be applied to the master branch, tested, and packaged in the next security release.[\/vc_column_text][\/vc_column_inner][vc_column_inner el_class=\u00a0\u00bbiconbox\u00a0\u00bb width=\u00a0\u00bb1\/4″][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-bullhorn\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text]The vulnerability will be publicly announced after the release.[\/vc_column_text][\/vc_column_inner][vc_column_inner el_class=\u00a0\u00bbiconbox\u00a0\u00bb width=\u00a0\u00bb1\/4″][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-award\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text]Finally, your name will be added to the\u00a0hall of fame<\/a> as a thank you from the entire Nextcloud community.[\/vc_column_text][\/vc_column_inner][vc_column_inner][vc_column_text css=\u00a0\u00bb.vc_custom_1667986173450{margin-top: 2rem !important;}\u00a0\u00bb]<\/p>\n

Read our threat model<\/a>\u00a0to know what is expected behavior.<\/p>\n

[\/vc_column_text][\/vc_column_inner][\/vc_row_inner][\/vc_column][\/vc_row][\/vc_section][vc_section el_class=\u00a0\u00bbnc_default_section lightBG\u00a0\u00bb css=\u00a0\u00bb.vc_custom_1667810946782{padding-top: 3rem !important;padding-bottom: 3rem !important;}\u00a0\u00bb][vc_row content_placement=\u00a0\u00bbmiddle\u00a0\u00bb][vc_column][vc_column_text]<\/p>\n

PGP Key for Submissions<\/h2>\n

[\/vc_column_text][vc_separator color=\u00a0\u00bbcustom\u00a0\u00bb border_width=\u00a0\u00bb2″ el_width=\u00a0\u00bb20″ accent_color=\u00a0\u00bb#0082c9″ el_class=\u00a0\u00bbnc_separator_line\u00a0\u00bb][vc_column_text]<\/p>\n

In order to facilitate secure submission of security issues,
\nwe provide the following\u00a0
PGP key<\/a>\u00a0for confidential submission:[\/vc_column_text][\/vc_column][\/vc_row][vc_row gap=\u00a0\u00bb20″ equal_height=\u00a0\u00bbyes\u00a0\u00bb content_placement=\u00a0\u00bbmiddle\u00a0\u00bb el_class=\u00a0\u00bbiconboxes\u00a0\u00bb][vc_column width=\u00a0\u00bb1\/4″][\/vc_column][vc_column width=\u00a0\u00bb1\/4″ el_class=\u00a0\u00bbiconbox\u00a0\u00bb][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-key\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text el_class=\u00a0\u00bbiconbox_title\u00a0\u00bb]<\/p>\n

Key ID<\/h4>\n

[\/vc_column_text][vc_column_text]A724937A<\/code>[\/vc_column_text][\/vc_column][vc_column width=\u00a0\u00bb1\/4″ el_class=\u00a0\u00bbiconbox\u00a0\u00bb][vc_icon icon_fontawesome=\u00a0\u00bbfas fa-fingerprint\u00a0\u00bb color=\u00a0\u00bbcustom\u00a0\u00bb custom_color=\u00a0\u00bb#0082c9″][vc_column_text el_class=\u00a0\u00bbiconbox_title\u00a0\u00bb]<\/p>\n

Fingerprint<\/h4>\n

[\/vc_column_text][vc_column_text]2880 6A87 8AE4 23A2 8372 792E D758 99B9 A724 937A<\/code>[\/vc_column_text][\/vc_column][vc_column width=\u00a0\u00bb1\/4″][\/vc_column][vc_column][vc_column_text]<\/p>\n

We do however recommend to not encrypt the information submitted
\nvia HackerOne as only a small subset of the team has access to this key.[\/vc_column_text][\/vc_column][\/vc_row][\/vc_section][vc_section el_class=\u00a0\u00bbnc_default_section\u00a0\u00bb css=\u00a0\u00bb.vc_custom_1667810243936{padding-top: 3rem !important;padding-bottom: 3rem !important;}\u00a0\u00bb][vc_row content_placement=\u00a0\u00bbmiddle\u00a0\u00bb][vc_column width=\u00a0\u00bb1\/2″][vc_column_text el_class=\u00a0\u00bbnc_text_as_separator centerMobile\u00a0\u00bb]Guidelines[\/vc_column_text][vc_column_text el_class=\u00a0\u00bbnc-section-title\u00a0\u00bb]<\/p>\n

Responsible disclosure
\nguidelines<\/h2>\n

[\/vc_column_text][vc_column_text css=\u00a0\u00bb.vc_custom_1667980771923{margin-top: 2rem !important;margin-bottom: 2rem !important;}\u00a0\u00bb]The Nextcloud community kindly requests that you comply with the following guidelines when researching and reporting security vulnerabilities:[\/vc_column_text][\/vc_column][vc_column width=\u00a0\u00bb1\/2″][vc_column_text]<\/p>\n