CVE-2020-8140: Code Injection
Published Mar 20, 2020
·Updated
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLDINSERTLIBRARIES set in the environment.
Affected Software
4 affected components
Nextcloud Desktop<2.6.3
Apple macOS
All of the following
Nextcloud Desktop<2.6.3
Apple macOS
Event History
Mar 20, 2020
CVE Published
via MITRE·08:20 PM
Data Sourced
via MITRE·08:20 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2020-8140?
CVE-2020-8140 is a code injection vulnerability in Nextcloud Desktop Client 2.6.2 for macOS.
2
How does CVE-2020-8140 affect Nextcloud Desktop?
CVE-2020-8140 allows an attacker to load arbitrary code when starting the Nextcloud Desktop Client with DYLD_INSERT_LIBRARIES set in the environment.
3
What is the severity of CVE-2020-8140?
The severity of CVE-2020-8140 is medium with a CVSS score of 6.7.
4
How can I fix CVE-2020-8140?
To fix CVE-2020-8140, update Nextcloud Desktop Client to version 2.6.3 or newer.
5
Where can I find more information about CVE-2020-8140?
You can find more information about CVE-2020-8140 on the HackerOne report and the Nextcloud security advisory.