Overview :
Multiple vulnerabilities reported in Nextcloud
Affected Product(s) :
  • Nextcloud Social app version 0.3.1
  • Nextcloud Social < 0.4.0
Vulnerability Details :
CVE ID : CVE-2020-8278
Improper access control in Nextcloud Social app version 0.3.1 allowed to read posts of any user.
CVE ID : CVE-2020-8279
Missing validation of server certificates for out-going connections in Nextcloud Social < 0.4.0 allowed a man-in-the-middle attack.

Solution :

This vulnerability is currently awaiting analysis.