{"affected":[{"ecosystem_specific":{"binaries":[{"nextcloud":"20.0.7-bp152.2.6.1","nextcloud-apache":"20.0.7-bp152.2.6.1"}]},"package":{"ecosystem":"SUSE:Package Hub 15 SP2","name":"nextcloud","purl":"pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"20.0.7-bp152.2.6.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for nextcloud fixes the following issues:\n\n- nextcloud was upgraded to version 20.0.7\n   - CVE-2020-8294: Fixed a missing link validation (boo#1181803)\n   - CVE-2020-8295: Fixed a denial of service attack (boo#1181804)\n   - CVE-2020-8293: Fixed an input validation issue (boo#1181445)\n\nThis update was imported from the openSUSE:Leap:15.2:Update update project.","id":"openSUSE-SU-2021:0274-1","modified":"2021-02-11T17:05:31Z","published":"2021-02-11T17:05:31Z","references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/IKPTLKOGRYW4NVA4XTNRDXSK534SPTR2/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181445"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181803"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181804"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8293"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8294"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8295"}],"related":["CVE-2020-8293","CVE-2020-8294","CVE-2020-8295"],"summary":"Security update for nextcloud","upstream":["CVE-2020-8293","CVE-2020-8294","CVE-2020-8295"]}