PT-2020-19954 · Nextcloud+1 · Nextcloud Server+1
Published
2018-12-05
·
Updated
2020-02-06
·
CVE-2020-8117
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Server version 14.0.3
Description
The issue is related to improper preservation of permissions, leading to the leakage of event details when a non-public event is shared.
Recommendations
For Nextcloud Server version 14.0.3, update to a version that fixes the permission preservation issue to prevent event detail leakage.
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Nextcloud Server