CVE-2020-8296
6.7MEDIUMNextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
Published: 3/3/2021Updated: 11/21/2024
Description
Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.
AI AnalysisPowered by AI
Affected Products
nextcloudnextcloud_server
fedoraprojectfedora
34
References
- https://github.com/nextcloud/server/issues/17439ExploitThird Party Advisory
- https://github.com/nextcloud/server/pull/21037PatchThird Party Advisory
- https://hackerone.com/reports/867164ExploitIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L6BO6P6MP2MOWA6PZRXX32PLWPXN5O4S/
- https://nextcloud.com/security/advisory/?id=NC-SA-2021-006Vendor Advisory
- https://github.com/nextcloud/server/issues/17439ExploitThird Party Advisory
- https://github.com/nextcloud/server/pull/21037PatchThird Party Advisory
- https://hackerone.com/reports/867164ExploitIssue TrackingThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/L6BO6P6MP2MOWA6PZRXX32PLWPXN5O4S/
- https://nextcloud.com/security/advisory/?id=NC-SA-2021-006Vendor Advisory