CVE Database
/

CVE-2020-8138

Back to search

CVE-2020-8138

Published: Mar 20, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

A missing check for IPv4 nested inside IPv6 in Nextcloud server < 17.0.1, < 16.0.7, and < 15.0.14 allowed a Server-Side Request Forgery (SSRF) vulnerability when subscribing to a malicious calendar URL.

VendorProductVersions

n/a

Nextcloud Server

affected
Fixed in 17.0.2, 16.0.7, and 15.0.14

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now