First published: Tue May 12 2020(Updated: )
An Insecure direct object reference vulnerability in Nextcloud Server 18.0.2 allowed an attacker to remote wipe devices of other users when sending a malicious request directly to the endpoint.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Server | <17.0.5 | |
Nextcloud Server | >=18.0.0<18.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8154 is classified as a high severity vulnerability due to its potential to allow unauthorized remote wipe of user devices.
To fix CVE-2020-8154, upgrade Nextcloud Server to version 18.0.3 or later, or 17.0.6 or a later version.
CVE-2020-8154 affects Nextcloud Server versions prior to 18.0.3 and versions up to but not including 17.0.5.
CVE-2020-8154 is an Insecure Direct Object Reference (IDOR) vulnerability.
The potential impacts of CVE-2020-8154 include the ability for attackers to remotely wipe the devices of other users.