A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
The product violates well-established principles for secure design.
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
Link | Tags |
---|---|
https://hackerone.com/reports/661051%2C | |
https://nextcloud.com/security/advisory/?id=NC-SA-2020-038 | broken link |
https://hackerone.com/reports/661051 | exploit third party advisory |