CVE-2020-8118
04.02.2020, 20:15
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
Vendor | Product | Version |
---|---|---|
nextcloud | nextcloud_server | 𝑥 < 15.0.9 |
nextcloud | nextcloud_server | 16.0.0 ≤ 𝑥 < 16.0.2 |
opensuse | backports_sle | 15.0:sp1 |
novell | suse_linux_enterprise_server | 12.0 |
𝑥
= Vulnerable software versions
References