This update for nextcloud fixes the following issues:
nextcloud version 20.0.0 fix some security issues:
- NC-SA-2020-037 PIN for passwordless WebAuthm is asked for but not
verified
- NC-SA-2020-033 (CVE-2020-8228) Missing rate limit on signup page
- NC-SA-2020-029 (CVE-2020-8233, boo#1177346) Re-Sharing allows increase
of privileges
- NC-SA-2020-026 Passowrd of share by mail is not hashed when given on
the create share call
- NC-SA-2020-023 Increase random used for encryption
- Update to 19.0.3
- Fix possible leaking scope in Flow (server#22410)
- Combine body-login rules in theming and fix twofactor and guest
styling on bright colors (server#22427)
- Show better quota warning for group folders and external storage
(server#22442)
- Add php docs build script (server#22448)
- Fix clicks on actions menu of non opaque file rows in acceptance tests
(server#22503)
- Fix writing...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2020-1652=1
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-1652=1
- openSUSE Backports SLE-15-SP2:
zypper in -t patch openSUSE-2020-1652=1
- openSUSE Backports SLE-15-SP1:
zypper in -t patch openSUSE-2020-1652=1
- openSUSE Leap 15.2 (noarch):
nextcloud-20.0.0-lp152.3.3.1
- openSUSE Leap 15.1 (noarch):
nextcloud-20.0.0-lp151.2.9.1
- openSUSE Backports SLE-15-SP2 (noarch):
nextcloud-20.0.0-bp152.2.3.1
- openSUSE Backports SLE-15-SP1 (noarch):
nextcloud-20.0.0-bp151.3.12.1
https://www.suse.com/security/cve/CVE-2020-8154.html
https://www.suse.com/security/cve/CVE-2020-8183.html
https://www.suse.com/security/cve/CVE-2020-8228.html
https://www.suse.com/security/cve/CVE-2020-8233.html
https://bugzilla.suse.com/1171572
https://bugzilla.suse.com/1171579
https://bugzilla.suse.com/1177346
--
Get the latest Linux and open source security news straight to your inbox.