PT-2020-19969 · Nextcloud · Nextcloud Server

Published

2020-11-09

·

Updated

2020-11-19

·

CVE-2020-8133

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server version 19.0.1
Description A wrong generation of the passphrase for the encrypted block allowed an attacker to overwrite blocks in a file.
Recommendations For Nextcloud Server version 19.0.1, update to a version that fixes the issue with the passphrase generation for encrypted blocks.

Exploit

Fix

Improper Verification of Cryptographic Signature

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8133

Affected Products

Nextcloud Server