CVE-2020-8139
20.03.2020, 21:15
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.Enginsight
Vendor | Product | Version |
---|---|---|
nextcloud | nextcloud_server | 16.0.0 ≤ 𝑥 < 16.0.9 |
nextcloud | nextcloud_server | 17.0.0 ≤ 𝑥 < 17.0.4 |
nextcloud | nextcloud_server | 18.0.0 ≤ 𝑥 < 18.0.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References