A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
| Software | From | Fixed in |
|---|---|---|
| nextcloud / nextcloud_server | 17.0.0 | 17.0.4 |
| nextcloud / nextcloud_server | 16.0.0 | 16.0.9 |
| nextcloud / nextcloud_server | 18.0.0 | 18.0.1 |
| fedoraproject / fedora | 32 | 32.x |