Improper Access Control in Nextcloud Social App
CVE-2020-8278

5.3MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
19 November 2020

What is CVE-2020-8278?

The Nextcloud Social app version 0.3.1 is affected by a vulnerability that permits unauthorized users to access and read posts created by any user within the application, leading to potential data exposure and privacy concerns. This issue arises from improper access control mechanisms, which fail to restrict access to sensitive data appropriately. Users looking to ensure their data remains secure should be aware of this flaw and consider applying necessary updates or security measures.

Affected Version(s)

Nextcloud Social Affects v0.3.1

Nextcloud Social Fixed in v0.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-8278 : Improper Access Control in Nextcloud Social App