First published: Fri Oct 30 2020(Updated: )
A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Server | <18.0.6 | |
Nextcloud Server | >=19.0.0<19.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8183 has a medium severity level due to the risk of sensitive data exposure.
To fix CVE-2020-8183, update Nextcloud Server to version 19.0.1 or later, or downgrade to version 18.0.6.
CVE-2020-8183 is a logic error that results in plaintext storage of the share password during the initial create API call.
CVE-2020-8183 affects Nextcloud Server versions 19.0.0 and 19.0.1, as well as all versions prior to 18.0.6.
CVE-2020-8183 can lead to unauthorized access to share passwords, compromising the confidentiality of shared content.