
Cloud Vulnerability DB
A community-led vulnerabilities database
A logic error was discovered in Nextcloud Server 19.0.0 that resulted in the plaintext storage of share passwords when provided during the initial create API call. The vulnerability was assigned CVE-2020-8183 and was reported through the HackerOne platform (CVE Details, Debian Tracker).
The vulnerability stems from a logic error in the password handling mechanism of Nextcloud Server 19.0.0. Specifically, when users created shares through the API and provided a password during the initial create call, the system stored these passwords in plaintext rather than using proper encryption (CVE Details).
The storage of share passwords in plaintext format could potentially expose sensitive access credentials if an attacker gained access to the storage system, compromising the security of shared resources (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."