Vulnerability Name:

CVE-2020-8294 (CCN-196144)

Assigned:2020-11-18
Published:2020-11-18
Updated:2021-02-05
Summary:A missing link validation in Nextcloud Server before 20.0.2, 19.0.5, 18.0.11 allows execution of a stored XSS attack using Internet Explorer when saving a 'javascript:' URL in markdown format.
CVSS v3 Severity:5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
3.0 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N)
2.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:N/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:3.5 Low (CVSS v2 Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2020-8294

Source: XF
Type: UNKNOWN
nextcloud-cve20208294-xss(196144)

Source: CONFIRM
Type: Permissions Required, Third Party Advisory
https://hackerone.com/reports/1023787

Source: CCN
Type: NC-SA-2021-002
Stored XSS in markdown file with Nextcloud Talk using Internet Explorer

Source: CONFIRM
Type: Vendor Advisory
https://nextcloud.com/security/advisory/?id=NC-SA-2021-002

Vulnerable Configuration:Configuration 1:
  • cpe:/a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* (Version < 18.0.11)
  • OR cpe:/a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* (Version >= 19.0.0 and < 19.0.5)
  • OR cpe:/a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* (Version >= 20.0.0 and < 20.0.2)

  • Configuration CCN 1:
  • cpe:/a:nextcloud:nextcloud_server:18.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:nextcloud:nextcloud_server:19.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:nextcloud:nextcloud_server:20.0.0:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:93630
    P
    (Important)
    2022-07-21
    oval:org.opensuse.security:def:100343
    P
    (Important)
    2021-10-26
    oval:org.opensuse.security:def:110978
    P
    Security update for nextcloud (Important)
    2021-07-20
    oval:org.opensuse.security:def:103101
    P
    Security update for nextcloud (Important)
    2021-07-20
    oval:org.opensuse.security:def:35508
    P
    Security update for nextcloud (Important)
    2021-07-20
    oval:org.opensuse.security:def:96411
    P
    Security update for nextcloud (Important)
    2021-07-20
    oval:org.opensuse.security:def:111486
    P
    Security update for nextcloud (Important)
    2021-07-20
    oval:org.opensuse.security:def:11104
    P
    Security update for nextcloud (Important)
    2021-07-20
    oval:org.opensuse.security:def:109758
    P
    Security update for nextcloud (Important)
    2021-07-20
    oval:org.opensuse.security:def:11176
    P
    Security update for nextcloud (Moderate)
    2021-02-11
    oval:org.opensuse.security:def:109792
    P
    Security update for nextcloud (Moderate)
    2021-02-11
    oval:org.opensuse.security:def:103135
    P
    Security update for nextcloud (Moderate)
    2021-02-11
    oval:org.opensuse.security:def:96445
    P
    Security update for nextcloud (Moderate)
    2021-02-11
    oval:org.opensuse.security:def:111211
    P
    Security update for nextcloud (Moderate)
    2021-02-08
    BACK
    nextcloud nextcloud server *
    nextcloud nextcloud server *
    nextcloud nextcloud server *
    nextcloud nextcloud server 18.0.0 -
    nextcloud nextcloud server 19.0.0 -
    nextcloud nextcloud server 20.0.0