CVE-2020-8173: Low severity nextcloud server vulnerability
Published Oct 30, 2020
·Updated
A too small set of random characters being used for encryption in Nextcloud Server 18.0.4 allowed decryption in shorter time than intended.
Affected Software
2 affected components
Nextcloud Server<17.0.7
Nextcloud Server>=18.0.0<18.0.5
Event History
Oct 30, 2020
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-8173?
CVE-2020-8173 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2020-8173?
To fix CVE-2020-8173, upgrade Nextcloud Server to version 18.0.5 or later, or to version 17.0.7 or later.
3
What are the affected versions for CVE-2020-8173?
CVE-2020-8173 affects Nextcloud Server versions prior to 18.0.5 and all versions below 17.0.7.
4
What type of vulnerability is CVE-2020-8173?
CVE-2020-8173 is an encryption vulnerability that allows decryption quicker than intended due to a small set of random characters.
5
Is CVE-2020-8173 exploitable?
Yes, CVE-2020-8173 is exploitable under certain conditions where attackers can leverage the flawed encryption mechanism.