CVE-2020-8279: High severity nextcloud social vulnerability
Published Nov 19, 2020
·Updated
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.
Affected Software
1 affected component
Nextcloud Social<0.4.0
Event History
Nov 19, 2020
CVE Published
via MITRE·12:32 AM
Data Sourced
via MITRE·12:32 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-8279?
CVE-2020-8279 has a CVSS score that indicates it is a critical vulnerability due to the potential for man-in-the-middle attacks.
2
How do I fix CVE-2020-8279?
To fix CVE-2020-8279, upgrade to Nextcloud Social version 0.4.0 or later.
3
What kind of attack does CVE-2020-8279 allow?
CVE-2020-8279 allows for man-in-the-middle attacks due to missing validation of server certificates.
4
Which versions of Nextcloud Social are affected by CVE-2020-8279?
CVE-2020-8279 affects all versions of Nextcloud Social prior to 0.4.0.
5
What should I do if I cannot upgrade due to CVE-2020-8279?
If you cannot upgrade due to CVE-2020-8279, ensure that your network is secure and consider applying additional network security measures.