
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-8118 is a server-side request forgery (SSRF) vulnerability discovered in Nextcloud server 16.0.1. The vulnerability allowed authenticated users to detect local and remote services when adding a new subscription in the calendar application (OpenSUSE Security, Debian Security).
The vulnerability is identified as an authenticated server-side request forgery (SSRF) that specifically affects the calendar application's subscription functionality in Nextcloud server version 16.0.1. The issue was tracked as NC-SA-2019-014 in Nextcloud's security advisory system (OpenSUSE Security).
When exploited, the vulnerability allows authenticated users to detect both local and remote services through the calendar application's subscription feature. This could potentially lead to unauthorized service discovery within the network infrastructure (Debian Security).
The vulnerability was addressed in Nextcloud version 15.0.14. Users are advised to upgrade to this version or later to receive the security fix. The update was distributed through various channels including SUSE Package Hub and openSUSE Backports (OpenSUSE Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."