Violation of Secure Design Principles
CVE-2020-8133
Summary
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
- LOW
- NETWORK
- LOW
- UNCHANGED
- NONE
- NONE
- NONE
- NONE
CWE-657 - Violation of Secure Design Principles
The product violates well-established principles for secure design.
References
Advisory Timeline
- Published