CVE-2020-8296 (https://nextcloud.com/security/advisory/?id=NC-SA-2021-006): Nextcloud Server prior to 20.0.0 stores passwords in a recoverable format even when external storage is not configured. CVE-2021-22877 (https://nextcloud.com/security/advisory/?id=NC-SA-2021-004): A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet. CVE-2021-22878 (https://nextcloud.com/security/advisory/?id=NC-SA-2021-005): Nextcloud Server prior to 20.0.6 is vulnerable to reflected cross-site scripting (XSS) due to lack of sanitization in `OC.Notification.show`. These are fixed in 20.0.6, please stabilize a suitable version.
amd64 stable
x86 stable. Maintainer(s), please cleanup. Security, please vote.
We currently cannot target multiple branches with unique slots per ebuild in GLSA. Repository is clean, all done.