First published: Mon Oct 05 2020(Updated: )
A logic error in Nextcloud Server 19.0.0 caused a privilege escalation allowing malicious users to reshare with higher permissions than they got assigned themselves.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Server | =19.0.0 | |
Red Hat Fedora | =32 | |
Red Hat Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-8223 is considered a high severity vulnerability due to potential privilege escalation.
To fix CVE-2020-8223, users should upgrade to a patched version of Nextcloud Server beyond 19.0.0.
CVE-2020-8223 affects Nextcloud Server version 19.0.0 and certain Fedora operating system versions.
CVE-2020-8223 is a logic error vulnerability that allows privilege escalation.
Yes, CVE-2020-8223 can be exploited remotely by malicious users to gain higher permissions.