描述
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.
AI分析AI驱动
受影响产品
nextcloudsocial
参考资料
- https://hackerone.com/reports/915585ExploitThird Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-043Broken LinkProduct
- https://hackerone.com/reports/915585ExploitThird Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-043Broken LinkProduct