Candidate: CVE-2020-8189 PublicDate: 2020-08-21 21:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8189 https://nextcloud.com/security/advisory/?id=NC-SA-2020-027 https://hackerone.com/reports/685552 Description: A cross-site scripting error in Nextcloud Desktop client 2.6.4 allowed to present any html (including local links) when responding with invalid data on the login attempt. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N [5.4 MEDIUM] Patches_nextcloud-desktop: upstream_nextcloud-desktop: needs-triage precise/esm_nextcloud-desktop: DNE trusty_nextcloud-desktop: ignored (out of standard support) trusty/esm_nextcloud-desktop: DNE xenial_nextcloud-desktop: DNE bionic_nextcloud-desktop: DNE focal_nextcloud-desktop: needs-triage groovy_nextcloud-desktop: ignored (reached end-of-life) hirsute_nextcloud-desktop: not-affected (3.0.1-3) impish_nextcloud-desktop: not-affected (3.0.1-3) jammy_nextcloud-desktop: not-affected (3.0.1-3) devel_nextcloud-desktop: not-affected (3.0.1-3)