PT-2020-20000 · Nextcloud+1 · Nextcloud Server+1

Published

2020-10-15

·

Updated

2022-09-27

·

CVE-2020-8173

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server version 18.0.4
Description A too small set of random characters being used for encryption allowed decryption in a shorter time than intended.
Recommendations For Nextcloud Server version 18.0.4, update to a version that uses a sufficient set of random characters for encryption to prevent decryption in a shorter time than intended.

Exploit

Fix

Missing Encryption of Sensitive Data

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3060
CVE-2020-8173

Affected Products

Alt Linux
Nextcloud Server