Bugzilla – Bug 1171572
VUL-1: CVE-2020-8155: Cross-site scripting vulnerability when opening a malicious PDF
Last modified: 2020-10-11 19:42:11 UTC
CVE-2020-8155 An outdated 3rd party library in the Files PDF viewer for Nextcloud Server 18.0.2 caused a Cross-site scripting vulnerability when opening a malicious PDF. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8155 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8155 https://nextcloud.com/security/advisory/?id=NC-SA-2020-019
Not sure whether Leap 15.1 is affected. Factory ships an already fixed version
(In reply to Alexandros Toptsoglou from comment #1) > Not sure whether Leap 15.1 is affected. Factory ships an already fixed > version Leap 15.1 has 15.0.14. Also 15.2 https://nextcloud.com/security/advisory/?id=NC-SA-2020-019 say: Affected Software: Nextcloud Server < 18.0.3 For 15.2 i have made an request from Factory to 15.2 Please make an maintenance request for 15.1
(In reply to Eric Schirra from comment #2) > (In reply to Alexandros Toptsoglou from comment #1) > > Not sure whether Leap 15.1 is affected. Factory ships an already fixed > > version > > Leap 15.1 has 15.0.14. > Also 15.2 > > https://nextcloud.com/security/advisory/?id=NC-SA-2020-019 say: > Affected Software: Nextcloud Server < 18.0.3 > > For 15.2 i have made an request from Factory to 15.2 > > Please make an maintenance request for 15.1 Hi Eric, maintenance requests are normally a task of the package maintainer and not of the security team's.
> Hi Eric, > > maintenance requests are normally a task of the package maintainer and not > of the security team's. You're right. Will do it in evening.
Maintenance request is done.
This is an autogenerated message for OBS integration: This bug (1171572) was mentioned in https://build.opensuse.org/request/show/805352 Backports:SLE-12 / nextcloud https://build.opensuse.org/request/show/805353 Backports:SLE-15-SP1 / nextcloud https://build.opensuse.org/request/show/805354 15.1 / nextcloud
openSUSE-SU-2020:0667-1: An update that solves two vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 1084320,1171572,1171579 CVE References: CVE-2020-8154,CVE-2020-8155 Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): nextcloud-18.0.4-22.1
openSUSE-SU-2020:0668-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1171572,1171579 CVE References: CVE-2020-8154,CVE-2020-8155 Sources used: openSUSE Backports SLE-15-SP1 (src): nextcloud-18.0.4-bp151.3.9.1
openSUSE-SU-2020:0670-1: An update that fixes two vulnerabilities is now available. Category: security (moderate) Bug References: 1171572,1171579 CVE References: CVE-2020-8154,CVE-2020-8155 Sources used: openSUSE Leap 15.1 (src): nextcloud-18.0.4-lp151.2.6.1
This is an autogenerated message for OBS integration: This bug (1171572) was mentioned in https://build.opensuse.org/request/show/839724 15.1+15.2+Backports:SLE-12+Backports:SLE-15-SP1+Backports:SLE-15-SP2 / nextcloud
openSUSE-SU-2020:1652-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1171572,1171579,1177346 CVE References: CVE-2020-8154,CVE-2020-8155,CVE-2020-8183,CVE-2020-8228,CVE-2020-8233 JIRA References: Sources used: openSUSE Leap 15.2 (src): nextcloud-20.0.0-lp152.3.3.1 openSUSE Leap 15.1 (src): nextcloud-20.0.0-lp151.2.9.1 openSUSE Backports SLE-15-SP2 (src): nextcloud-20.0.0-bp152.2.3.1 openSUSE Backports SLE-15-SP1 (src): nextcloud-20.0.0-bp151.3.12.1
openSUSE-SU-2020:1652-1: An update that fixes 5 vulnerabilities is now available. Category: security (moderate) Bug References: 1171572,1171579,1177346 CVE References: CVE-2020-8154,CVE-2020-8155,CVE-2020-8183,CVE-2020-8228,CVE-2020-8233 JIRA References: Sources used: openSUSE Leap 15.2 (src): nextcloud-20.0.0-lp152.3.3.1 openSUSE Leap 15.1 (src): nextcloud-20.0.0-lp151.2.9.1 openSUSE Backports SLE-15-SP2 (src): nextcloud-20.0.0-bp152.2.3.1 openSUSE Backports SLE-15-SP1 (src): nextcloud-20.0.0-bp151.3.12.1 SUSE Package Hub for SUSE Linux Enterprise 12 (src): nextcloud-20.0.0-25.1
Nextcloud is updated to 20.