First published: Tue May 12 2020(Updated: )
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Group Folders | <4.0.4 | |
Red Hat Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8153 has a medium severity level as it involves improper access control that can lead to unintended deletion of directories.
To fix CVE-2020-8153, upgrade your Nextcloud Group Folders app to version 4.0.4 or later.
CVE-2020-8153 affects Nextcloud Group Folders version 4.0.3 and earlier, as well as Fedora version 32.
The impact of CVE-2020-8153 is that it allows the deletion of hidden directories when renaming an accessible item to the same name.
Currently, the recommended solution for CVE-2020-8153 is to update the software rather than implement a workaround.