PT-2020-19991 · Nextcloud · Nextcloud Mail
Published
2020-05-12
·
Updated
2024-11-20
·
CVE-2020-8156
CVSS v3.1
7.0
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Nextcloud Mail version 1.1.3
Description
A missing verification of the TLS host allowed a man-in-the-middle attack.
Recommendations
For Nextcloud Mail version 1.1.3, update to a version that includes the fix for the missing TLS host verification to prevent man-in-the-middle attacks.
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nextcloud Mail