First published: Tue Feb 04 2020(Updated: )
A missing check in Nextcloud Server 14.0.3 could give recipient the possibility to extend the expiration date of a share they received.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Server | <12.0.13 | |
Nextcloud Server | >=13.0.0<13.0.8 | |
Nextcloud Server | >=14.0.0<14.0.4 | |
Nextcloud Server | >=14.0.5<15.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8122 is considered a medium severity vulnerability due to the potential for unauthorized expiration date manipulation.
To fix CVE-2020-8122, upgrade your Nextcloud Server to version 14.0.4 or later, or to versions 13.0.8 and below 14.0.0.
CVE-2020-8122 allows a recipient of a shared file to extend the expiration date of their share without permission from the sender.
If you are using Nextcloud Server versions below 14.0.4, between 13.0.0 and 13.0.8, or between 14.0.0 and 14.0.5, you are vulnerable to CVE-2020-8122.
Any user of Nextcloud Server versions that fall within the specified vulnerable ranges is at risk of exploitation from CVE-2020-8122.