Disabled download shares still allow download through preview images

Disclosed: 2022-12-31 09:33:06 By juliushaertl To nextcloud
Low
Vulnerability Details
## Summary: ## Steps To Reproduce: 1. Share a folder and disable the "Allow download" permission 2. Now as the recipient of the file you can still download the preview of the file This is an issue for images but also for shared documents where viewing them in Collabora would present them watermarked but the preview would leak the first page without an watermark. ## Impact Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked.
Actions
View on HackerOne
Report Stats
  • Report ID: 1745766
  • State: Closed
  • Substate: resolved
  • Upvotes: 14
Share this report