Vulnerability Description
A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud Server | < 19.0.2 |
Related Weaknesses (CWE)
References
- http://seclists.org/fulldisclosure/2020/Dec/55Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/57Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/58Mailing ListThird Party Advisory
- https://hackerone.com/reports/742588ExploitThird Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-039Vendor Advisory
- http://seclists.org/fulldisclosure/2020/Dec/55Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/57Mailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2020/Dec/58Mailing ListThird Party Advisory
- https://hackerone.com/reports/742588ExploitThird Party Advisory
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-039Vendor Advisory
FAQ
What is CVE-2020-8150?
CVE-2020-8150 is a vulnerability with a CVSS score of 4.1 (MEDIUM). A cryptographic issue in Nextcloud Server 19.0.1 allowed an attacker to downgrade the encryption scheme and break the integrity of encrypted files.
How severe is CVE-2020-8150?
CVE-2020-8150 has been rated MEDIUM with a CVSS base score of 4.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8150?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Nextcloud Server.