First published: Tue May 12 2020(Updated: )
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
Credit: support@hackerone.com support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Mail | <1.1.4 | |
Fedoraproject Fedora | =32 | |
Nextcloud mail | <1.1.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-8156.
The severity of CVE-2020-8156 is high.
CVE-2020-8156 allows a man-in-the-middle attack in Nextcloud Mail 1.1.3 due to a missing verification of the TLS host.
To fix CVE-2020-8156, update Nextcloud Mail to version 1.1.4 or higher.