Unrated severityNVD Advisory· Published Mar 20, 2020· Updated Aug 4, 2024
CVE-2020-8139
CVE-2020-8139
Description
A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.
Affected products
1- Range: Fixed in 18.0.1, 17.0.4, and 16.0.9
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/KC6HLX5SG4PZO6Y54D2LFJ4ATG76BKOP/mitrevendor-advisoryx_refsource_FEDORA
- hackerone.com/reports/788257mitrex_refsource_MISC
- nextcloud.com/security/advisory/mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.