A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
References
Link | Resource |
---|---|
https://hackerone.com/reports/661051, | Broken Link |
https://nextcloud.com/security/advisory/?id=NC-SA-2020-038 | Broken Link |
https://hackerone.com/reports/661051 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-11-09 07:15
Updated : 2020-11-19 08:10
NVD link : CVE-2020-8133
Mitre link : CVE-2020-8133
JSON object : View
CWE
CWE-347
Improper Verification of Cryptographic Signature
Products Affected
nextcloud
- nextcloud_server