Bugzilla – Bug 1180929
VUL-0: CVE-2020-8225: nextcloud-desktop: cleartext storage of sensitive information
Last modified: 2021-02-28 18:48:15 UTC
CVE-2020-8225 A cleartext storage of sensitive information in Nextcloud Desktop Client 2.6.4 gave away information about used proxies and their authentication credentials. References: https://hackerone.com/reports/685990 https://nextcloud.com/security/advisory/?id=NC-SA-2020-031 References: https://bugzilla.redhat.com/show_bug.cgi?id=1914205 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-8225 http://people.canonical.com/~ubuntu-security/cve/2020/CVE-2020-8225.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8225 https://hackerone.com/reports/685990 https://nextcloud.com/security/advisory/?id=NC-SA-2020-031
Request for updates are done.
This is an autogenerated message for OBS integration: This bug (1180929) was mentioned in https://build.opensuse.org/request/show/872585 15.2 / nextcloud-desktop https://build.opensuse.org/request/show/872587 Backports:SLE-15-SP2 / nextcloud-desktop
3.1.2 now in tepis so mit think it can close.