CVE Database
/

CVE-2020-8139

Back to search

CVE-2020-8139

Published: Mar 20, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

A missing access control check in Nextcloud Server < 18.0.1, < 17.0.4, and < 16.0.9 causes hide-download shares to be downloadable when appending /download to the URL.

VendorProductVersions

n/a

Nextcloud Server

affected
Fixed in 18.0.1, 17.0.4, and 16.0.9

Weaknesses (CWE)

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now