Medium severity5.0NVD Advisory· Published Feb 4, 2020· Updated Jun 17, 2026
CVE-2020-8118
CVE-2020-8118
Description
An authenticated server-side request forgery in Nextcloud server 16.0.1 allowed to detect local and remote services when adding a new subscription in the calendar application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9- cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
- cpe:2.3:o:novell:suse_linux_enterprise_server:12.0:-:*:*:*:*:*:*
- Range: =16.0.1
- osv-coords4 versionspkg:rpm/opensuse/nextcloud&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2012pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015%20SP1
< 15.0.14-bp151.3.3.1+ 3 more
- (no CPE)range: < 15.0.14-bp151.3.3.1
- (no CPE)range: < 15.0.14-bp151.3.3.1
- (no CPE)range: < 15.0.14-bp151.3.3.1
- (no CPE)range: < 15.0.14-bp151.3.3.1
Patches
Vulnerability mechanics
References
4- hackerone.com/reports/427835nvdExploitThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-02/msg00019.htmlnvdRelease NotesThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-02/msg00022.htmlnvdRelease NotesThird Party Advisory
- nextcloud.com/security/advisory/nvdVendor Advisory
News mentions
0No linked articles in our index yet.