CVE-2020-8122: Input Validation
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-8122?
CVE-2020-8122 is considered a medium severity vulnerability due to the potential for unauthorized expiration date manipulation.
How do I fix CVE-2020-8122?
To fix CVE-2020-8122, upgrade your Nextcloud Server to version 14.0.4 or later, or to versions 13.0.8 and below 14.0.0.
What impact does CVE-2020-8122 have on Nextcloud Server?
CVE-2020-8122 allows a recipient of a shared file to extend the expiration date of their share without permission from the sender.
Is my version of Nextcloud Server vulnerable to CVE-2020-8122?
If you are using Nextcloud Server versions below 14.0.4, between 13.0.0 and 13.0.8, or between 14.0.0 and 14.0.5, you are vulnerable to CVE-2020-8122.
Who is affected by CVE-2020-8122?
Any user of Nextcloud Server versions that fall within the specified vulnerable ranges is at risk of exploitation from CVE-2020-8122.