This update for nextcloud fixes the following issues:
Update to 20.0.12
Fix boo#1190291
- CVE-2021-32766 (CWE-209): Generation of Error Message Containing
Sensitive Information
- CVE-2021-32800 (CWE-306): Missing Authentication for Critical Function
- CVE-2021-32801 (CWE-532): Insertion of Sensitive Information into Log
File
- CVE-2021-32802 (CWE-829): Inclusion of Functionality from Untrusted
Control Sphere
Changes
- Bump vue-router from 3.4.3 to 3.4.9 (server#27224)
- Bump v-click-outside from 3.1.1 to 3.1.2 (server#27232)
- Bump url-search-params-polyfill from 8.1.0 to 8.1.1 (server#27236)
- Bump debounce from 1.2.0 to 1.2.1 (server#27646)
- Bump vue and vue-template-compiler (server#27701)
- Design fixes to app-settings button (server#27745)
- Reset checksum when writing files to object store (server#27754)
- Run s3 tests again (server#27804)
- Fix in locking cache check (server#27829)
- Bump dompurify from...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP3:
zypper in -t patch openSUSE-2021-1255=1
- openSUSE Backports SLE-15-SP3 (noarch):
nextcloud-20.0.12-bp153.2.6.1
nextcloud-apache-20.0.12-bp153.2.6.1
https://www.suse.com/security/cve/CVE-2021-32766.html
https://www.suse.com/security/cve/CVE-2021-32800.html
https://www.suse.com/security/cve/CVE-2021-32801.html
https://www.suse.com/security/cve/CVE-2021-32802.html
https://bugzilla.suse.com/1190291
Get the latest Linux and open source security news straight to your inbox.