Improper Access Control Vulnerability in Nextcloud Deck by Nextcloud
CVE-2020-8179

4.1MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
2 July 2020

What is CVE-2020-8179?

An improper access control vulnerability in Nextcloud Deck version 1.0.0 allows malicious users to inject tasks into other users' decks. This flaw can lead to unauthorized access and manipulation of task data, potentially compromising sensitive information. It is vital for users to ensure they are running updated versions of Nextcloud Deck to mitigate these risks.

Affected Version(s)

Nextcloud Deck Fixed in 1.0.1

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.