CVE-2020-8119: Medium severity Nextcloud Server vulnerability
Published Feb 4, 2020
·Updated
Improper authorization in Nextcloud server 17.0.0 causes leaking of previews and files when a file-drop share link is opened via the gallery app.
Affected Software
3 affected components
Nextcloud Server<15.0.13
Nextcloud Server>=16.0.0<16.0.6
Nextcloud Server>=17.0.0<17.0.1
Event History
Feb 4, 2020
CVE Published
via MITRE·07:08 PM
Data Sourced
via MITRE·07:08 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8119?
CVE-2020-8119 is classified as a medium severity vulnerability that allows unauthorized access to file previews and files.
2
How do I fix CVE-2020-8119?
To fix CVE-2020-8119, update Nextcloud server to version 17.0.1 or later, or ensure your installation is below version 15.0.13.
3
What impact does CVE-2020-8119 have on Nextcloud server users?
CVE-2020-8119 can lead to unauthorized file access and exposure of sensitive file previews when file-drop links are shared.
4
Which versions of Nextcloud are affected by CVE-2020-8119?
CVE-2020-8119 affects Nextcloud server versions 17.0.0 and 16.0.0 to 16.0.6, and 15.0.0 to 15.0.13.
5
Is CVE-2020-8119 a remote code execution vulnerability?
CVE-2020-8119 is not a remote code execution vulnerability; it primarily involves improper authorization leading to file exposure.