Vulnerability Description
Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Group Folders | < 4.0.4 |
| Fedoraproject | Fedora | 32 |
Related Weaknesses (CWE)
References
- https://hackerone.com/reports/642515ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-017Vendor Advisory
- https://hackerone.com/reports/642515ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-017Vendor Advisory
FAQ
What is CVE-2020-8153?
CVE-2020-8153 is a vulnerability with a CVSS score of 8.1 (HIGH). Improper access control in Groupfolders app 4.0.3 allowed to delete hidden directories when when renaming an accessible item to the same name.
How severe is CVE-2020-8153?
CVE-2020-8153 has been rated HIGH with a CVSS base score of 8.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-8153?
Check the references section above for vendor advisories and patch information. Affected products include: Nextcloud Group Folders, Fedoraproject Fedora.