CVE-2020-8156: High severity nextcloud mail vulnerability
Published May 12, 2020
·Updated
A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.
Affected Software
3 affected components
Nextcloud mail<1.1.4
Fedoraproject Fedora=32
Nextcloud Nextcloud mail<1.1.4
Event History
May 12, 2020
CVE Published
via MITRE·01:01 PM
Data Sourced
via MITRE·01:01 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-8156.
2
What is the severity of CVE-2020-8156?
The severity of CVE-2020-8156 is high.
3
How does CVE-2020-8156 impact Nextcloud Mail?
CVE-2020-8156 allows a man-in-the-middle attack in Nextcloud Mail 1.1.3 due to a missing verification of the TLS host.
4
How can I fix CVE-2020-8156?
To fix CVE-2020-8156, update Nextcloud Mail to version 1.1.4 or higher.