Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
References
Link | Resource |
---|---|
https://nextcloud.com/security/advisory/?id=NC-SA-2020-042 | Broken Link Product |
https://hackerone.com/reports/921717 | Exploit Third Party Advisory |
Configurations
Information
Published : 2020-11-18 17:15
Updated : 2020-12-02 12:14
NVD link : CVE-2020-8278
Mitre link : CVE-2020-8278
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
nextcloud
- social