CVE-2020-8133
CVE-2020-8133 is a medium-severity vulnerability in Nextcloud Nextcloud Server with a CVSS 3.x base score of 5.3. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-347.
Key facts
- Severity: Medium (CVSS 3.x base score 5.3)
- CVSS v2: 5.0
- EPSS exploit prediction: 1% (51st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-347
- Affected product: Nextcloud Nextcloud Server
- Published:
- Last modified:
Description
A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
Frequently asked questions
- What is CVE-2020-8133?
- A wrong generation of the passphrase for the encrypted block in Nextcloud Server 19.0.1 allowed an attacker to overwrite blocks in a file.
- How severe is CVE-2020-8133?
- CVE-2020-8133 has a CVSS 3.x base score of 5.3, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability none.
- Is CVE-2020-8133 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (51st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2020-8133?
- CVE-2020-8133 affects Nextcloud Nextcloud Server. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2020-8133?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2020-8133 published?
- CVE-2020-8133 was published on 2020-11-09 and last updated on 2026-06-17.
References
- https://hackerone.com/reports/661051%2C
- https://nextcloud.com/security/advisory/?id=NC-SA-2020-038
- https://hackerone.com/reports/661051
Affected products (1)
- cpe:2.3:a:nextcloud:nextcloud_server:19.0.1:*:*:*:*:*:*:*
More vulnerabilities in Nextcloud Nextcloud Server
- CVE-2021-22915 — Critical (CVSS 9.8): Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6…
- CVE-2021-32802 — Critical (CVSS 9.3): Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user…
- CVE-2023-26482 — Critical (CVSS 9.0): Nextcloud server is an open source home cloud implementation. In affected versions a missing scope validation allowed…
- CVE-2021-32688 — High (CVSS 8.8): Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific…
- CVE-2018-3775 — High (CVSS 8.8): Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user…
- CVE-2023-35172 — High (CVSS 8.7): NextCloud Server and NextCloud Enterprise Server provide file storage for Nextcloud, a self-hosted productivity…
All CVEs affecting Nextcloud Nextcloud Server →
Other CWE-347 (Improper Verification of Cryptographic Signature) vulnerabilities
- CVE-2026-5430 — Critical (CVSS 10.0): The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or…
- CVE-2026-56451 — Critical (CVSS 10.0): A vulnerability has been identified in Opcenter X (All versions < V2604). Affected applications do not properly…
- CVE-2026-48558 — Critical (CVSS 10.0): SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the…
- CVE-2023-25574 — Critical (CVSS 10.0): `jupyterhub-ltiauthenticator` is a JupyterHub authenticator for learning tools interoperability (LTI).…
- CVE-2024-45409 — Critical (CVSS 10.0): The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <=…
- CVE-2024-32962 — Critical (CVSS 10.0): xml-crypto is an xml digital signature and encryption library for Node.js. In affected versions the default…
Browse all CWE-347 (Improper Verification of Cryptographic Signature) vulnerabilities →