CVE-2020-8138: SSRF
Published Mar 20, 2020
·Updated
A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.
Affected Software
3 affected components
Nextcloud Server<15.0.14
Nextcloud Server>=16.0.0<16.0.7
Nextcloud Server>=17.0.0<17.0.2
Event History
Mar 20, 2020
CVE Published
via MITRE·08:12 PM
Data Sourced
via MITRE·08:12 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2020-8138?
CVE-2020-8138 has a medium severity rating, indicating that it poses a notable risk.
2
How do I fix CVE-2020-8138?
To fix CVE-2020-8138, upgrade your Nextcloud server to version 15.0.14, 16.0.7, or 17.0.1 or later.
3
What systems are affected by CVE-2020-8138?
CVE-2020-8138 affects Nextcloud server versions earlier than 15.0.14, 16.0.7, and 17.0.1.
4
What type of vulnerability is CVE-2020-8138?
CVE-2020-8138 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
5
What consequences can arise from CVE-2020-8138?
Exploitation of CVE-2020-8138 can lead to unauthorized access to internal network resources.