CVE-2020-8297Authorization Bypass Through User-Controlled Key in Deck

Severity
4.3MEDIUMNVD
EPSS
0.2%
top 53.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 23
Latest updateMay 24

Description

Nextcloud Deck before 1.0.2 suffers from an insecure direct object reference (IDOR) vulnerability that permits users with a duplicate user identifier to access deck data of a previous deleted user.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages1 packages

NVDnextcloud/deck< 1.0.2

Patches

🔴Vulnerability Details

2
GHSA
GHSA-hx5m-93g9-j2jh: Nextcloud Deck before 12022-05-24
CVEList
CVE-2020-8297: Nextcloud Deck before 12021-02-23
CVE-2020-8297 — Nextcloud Deck vulnerability | cvebase