CVE-2020-8121
04.02.2020, 20:15
A bug in Nextcloud Server 14.0.4 could expose more data in reshared link shares than intended by the sharer.Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | nextcloud_server | 𝑥 < 13.0.9 |
nextcloud | nextcloud_server | 14.0.0 ≤ 𝑥 < 14.0.5 |
nextcloud | nextcloud_server | 14.0.6 ≤ 𝑥 < 15.0.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-284 - Improper Access ControlThe software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
- CWE-668 - Exposure of Resource to Wrong SphereThe product exposes a resource to the wrong control sphere, providing unintended actors with inappropriate access to the resource.