Nextcloud.User-Agent.Handling.Log.Evasion

description-logoDescription

This indicates an attack attempt against a Log Evasion vulnerability in Nextcloud.
The vulnerability is due to inadequate filtering of special character which leads to the log file not logging an action. A remote attacker may be able to exploit this to avoid having their actions recorded in the log file.

affected-products-logoAffected Products

Nextcloud Server < 12.0.3
Nextcloud Server < 11.0.5

Impact logoImpact

Security Bypass: Remote attackers can avoid having their actions being logged.

recomended-action-logoRecommended Actions

Upgrade to Nextcloud Server 12.0.3 or 11.0.5.
https://nextcloud.com/install/

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)