CVE-2020-8296
6.7MEDIUMNextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
Veröffentlicht: 3/3/2021Aktualisiert: 11/21/2024
Beschreibung
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
KI-AnalyseKI-gestützt
Betroffene Produkte
nextcloudnextcloud_server
fedoraprojectfedora
34
Referenzen
- https://github.com/nextcloud/server/issues/17439ExploitThird Party Advisory
- https://github.com/nextcloud/server/pull/21037PatchThird Party Advisory
- https://hackerone.com/reports/867164ExploitIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L6BO6P6MP2MOWA6PZRXX32PLWPXN5O4S/
- https://nextcloud.com/security/advisory/?id=NC-SA-2021-006Vendor Advisory
- https://github.com/nextcloud/server/issues/17439ExploitThird Party Advisory
- https://github.com/nextcloud/server/pull/21037PatchThird Party Advisory
- https://hackerone.com/reports/867164ExploitIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L6BO6P6MP2MOWA6PZRXX32PLWPXN5O4S/
- https://nextcloud.com/security/advisory/?id=NC-SA-2021-006Vendor Advisory