CVE-2020-8117: Medium severity Nextcloud Server vulnerability
Published Feb 4, 2020
·Updated
Improper preservation of permissions in Nextcloud Server 14.0.3 causes the event details to be leaked when sharing a non-public event.
Affected Software
3 affected components
Nextcloud Server<12.0.13
Nextcloud Server>=13.0.0<13.0.8
Nextcloud Server>=14.0.0<14.0.4
Event History
Feb 4, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8117?
CVE-2020-8117 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-8117?
To fix CVE-2020-8117, upgrade Nextcloud Server to version 14.0.4 or later.
3
What impact does CVE-2020-8117 have on non-public event sharing?
CVE-2020-8117 allows the details of non-public events to be leaked when shared.
4
Which versions of Nextcloud Server are affected by CVE-2020-8117?
Nextcloud Server versions prior to 14.0.4, as well as 13.0.0 to 13.0.8, and 12.0.13 and below are affected by CVE-2020-8117.
5
Is CVE-2020-8117 specific to any specific type of event in Nextcloud Server?
Yes, CVE-2020-8117 specifically affects the sharing of non-public events in Nextcloud Server.