Bugzilla – Bug 1175663
VUL-0: CVE-2020-8227: nextcloud-desktop: missing sanitization of a server response
Last modified: 2021-09-14 07:22:26 UTC
CVE-2020-8227 Missing sanitization of a server response in Nextcloud Desktop Client 2.6.4 for Linux allowed a malicious Nextcloud Server to store files outside of the dedicated sync directory. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8227 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8227 https://hackerone.com/reports/590319 https://nextcloud.com/security/advisory/?id=NC-SA-2020-032
Hi Alexei, I'm not quite sure whether it is correct to assign it to you, please feel free to reassign it whenever necessary, thanks.
This entry is very old. We are now on 3.1.3. So it should be fixed.