First published: Tue Feb 04 2020(Updated: )
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | <15.0.13 | |
Nextcloud Nextcloud Server | >=16.0.0<16.0.6 | |
Nextcloud Nextcloud Server | >=17.0.0<17.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8119 is classified as a medium severity vulnerability that allows unauthorized access to file previews and files.
To fix CVE-2020-8119, update Nextcloud server to version 17.0.1 or later, or ensure your installation is below version 15.0.13.
CVE-2020-8119 can lead to unauthorized file access and exposure of sensitive file previews when file-drop links are shared.
CVE-2020-8119 affects Nextcloud server versions 17.0.0 and 16.0.0 to 16.0.6, and 15.0.0 to 15.0.13.
CVE-2020-8119 is not a remote code execution vulnerability; it primarily involves improper authorization leading to file exposure.