First published: Fri Mar 20 2020(Updated: )
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Server | <15.0.14 | |
Nextcloud Server | >=16.0.0<16.0.7 | |
Nextcloud Server | >=17.0.0<17.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8138 has a medium severity rating, indicating that it poses a notable risk.
To fix CVE-2020-8138, upgrade your Nextcloud server to version 15.0.14, 16.0.7, or 17.0.1 or later.
CVE-2020-8138 affects Nextcloud server versions earlier than 15.0.14, 16.0.7, and 17.0.1.
CVE-2020-8138 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Exploitation of CVE-2020-8138 can lead to unauthorized access to internal network resources.