First published: Mon Oct 05 2020(Updated: )
Missing access control in Nextcloud Deck 1.0.4 caused an insecure direct object reference allowing an attacker to view all attachments.
Credit: support@hackerone.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Deck | =1.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-8235.
The severity level of CVE-2020-8235 is medium (4.3).
The cause of CVE-2020-8235 vulnerability is missing access control in Nextcloud Deck 1.0.4.
The impact of CVE-2020-8235 vulnerability is that it allows an attacker to view all attachments.
To fix CVE-2020-8235 vulnerability, you should update Nextcloud Deck to a version that includes the fix.