A logic error in Nextcloud Server 19.0.0 caused a plaintext storage of the share password when it was given on the initial create API call.
Storing a password in plaintext may result in a system compromise.
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
Link | Tags |
---|---|
https://nextcloud.com/security/advisory/?id=NC-SA-2020-026 | broken link vendor advisory |
https://hackerone.com/reports/885041 | third party advisory exploit |