PT-2020-20039 · Nextcloud · Nextcloud Desktop Client

Published

2020-08-21

·

Updated

2022-09-27

·

CVE-2020-8227

CVSS v2.0

7.1

High

VectorAV:N/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop Client version 2.6.4
Description The issue is related to missing sanitization of a server response in the Nextcloud Desktop Client, which allows a malicious Nextcloud Server to store files outside of the dedicated sync directory.
Recommendations For Nextcloud Desktop Client version 2.6.4, update to a newer version that addresses this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2020-8227

Affected Products

Nextcloud Desktop Client