Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 774252 (CVE-2020-8296, CVE-2021-22877, CVE-2021-22878) - <www-apps/nextcloud-20.0.6: multiple vulnerabilities (CVE-2020-8296, CVE-2021-{22877,22878})
Summary: <www-apps/nextcloud-20.0.6: multiple vulnerabilities (CVE-2020-8296, CVE-2021...
Alias: CVE-2020-8296, CVE-2021-22877, CVE-2021-22878
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
Whiteboard: B4 [noglsa cve]
Depends on:
Reported: 2021-03-05 02:51 UTC by John Helmert III
Modified: 2021-05-25 16:30 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---
nattka: sanity-check+


Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-03-05 02:51:29 UTC
CVE-2020-8296 (

Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured.

CVE-2021-22877 (

A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.

CVE-2021-22878 (

Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in ``.

These are fixed in 20.0.6, please stabilize a suitable version.
Comment 1 Agostino Sarubbo gentoo-dev 2021-03-05 14:18:48 UTC
amd64 stable
Comment 2 Agostino Sarubbo gentoo-dev 2021-03-05 14:19:46 UTC
x86 stable.

Maintainer(s), please cleanup.
Security, please vote.
Comment 3 Thomas Deutschmann (RETIRED) gentoo-dev 2021-05-25 16:30:09 UTC
We currently cannot target multiple branches with unique slots per ebuild in GLSA.

Repository is clean, all done.