CVE-2020-8225: High severity nextcloud desktop client vulnerability
Published Sep 18, 2020
·Updated
A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials.
Affected Software
1 affected component
Nextcloud Desktop<2.6.5
Event History
Sep 18, 2020
CVE Published
via MITRE·08:11 PM
Data Sourced
via MITRE·08:11 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2020-8225.
2
What is the severity of CVE-2020-8225?
The severity of CVE-2020-8225 is high.
3
What is the affected software?
The affected software is Nextcloud Desktop Client version up to exclusive 2.6.5.
4
How does CVE-2020-8225 expose sensitive information?
CVE-2020-8225 exposes sensitive information through cleartext storage of proxies and their authentication credentials.
5
Where can I find more information about CVE-2020-8225?
You can find more information about CVE-2020-8225 in the HackerOne report (link: https://hackerone.com/reports/685990) and the Nextcloud security advisory (link: https://nextcloud.com/security/advisory/?id=NC-SA-2020-031).