CVE-2020-8153: High severity nextcloud groupfolders vulnerability
Published May 12, 2020
·Updated
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
Affected Software
2 affected components
Nextcloud Group Folders<4.0.4
Fedoraproject Fedora=32
Event History
May 12, 2020
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-8153?
CVE-2020-8153 has a medium severity level as it involves improper access control that can lead to unintended deletion of directories.
2
How do I fix CVE-2020-8153?
To fix CVE-2020-8153, upgrade your Nextcloud Group Folders app to version 4.0.4 or later.
3
Which software is affected by CVE-2020-8153?
CVE-2020-8153 affects Nextcloud Group Folders version 4.0.3 and earlier, as well as Fedora version 32.
4
What is the impact of CVE-2020-8153?
The impact of CVE-2020-8153 is that it allows the deletion of hidden directories when renaming an accessible item to the same name.
5
Is there a workaround for CVE-2020-8153?
Currently, the recommended solution for CVE-2020-8153 is to update the software rather than implement a workaround.