First published: Tue Feb 04 2020(Updated: )
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | <13.0.9 | |
Nextcloud Nextcloud Server | >=14.0.0<14.0.5 | |
Nextcloud Nextcloud Server | >=14.0.6<15.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8121 is classified as a medium severity vulnerability due to the potential exposure of sensitive data.
To fix CVE-2020-8121, upgrade Nextcloud Server to version 14.0.5 or later, or to version 15.0.0 or later.
CVE-2020-8121 affects Nextcloud Server versions prior to 14.0.5 and versions between 14.0.0 and 14.0.4.
CVE-2020-8121 is a data exposure vulnerability that can unintentionally expose more data than intended.
Using Nextcloud Server 13.0.9 is still affected by other vulnerabilities, so it is recommended to upgrade to a secure version.