# Fixes for CVE-2020-8259/CVE-2020-8152 in Nextcloud 18/19

**URL:** <https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289>\
**Category:** 🏷️ General\
**Tags:** nc19, nc18-nextcloud-hub, cve\
**Created:** [November 16, 2020, 3:19pm UTC](https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289 "2020-11-16T15:19:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![lcts](https://help.nextcloud.com/user_avatar/help.nextcloud.com/lcts/32/32174_2.png) [@lcts](https://help.nextcloud.com/u/lcts)\
**Post date:** [November 16, 2020, 3:19pm UTC](https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289/1 "2020-11-16T15:19:12Z")

</div>

[NC-SA-2020-041 / CVE-2020-8259](https://nextcloud.com/security/advisory/?id=NC-SA-2020-041) and [NC-SA-2020-04 / CVE-2020-8152](https://nextcloud.com/security/advisory/?id=NC-SA-2020-040) were reported against 19.0.1 a couple of months ago. The advisory states that they’re fixed in 20.0.0+, but it seems the fix hasn’t been backported to NC18/19 (yet?).

Does anyone know what the status of these CVEs is in NC19 and NC18?

---

<div class="post-metadata">

**Author:** ![j-ed](https://help.nextcloud.com/user_avatar/help.nextcloud.com/j-ed/32/7281_2.png) [@j-ed](https://help.nextcloud.com/u/j-ed)\
**Post date:** [November 16, 2020, 3:25pm UTC](https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289/2 "2020-11-16T15:25:06Z")

</div>

@jospoortvliet Can you please answer this question.

---

<div class="post-metadata">

**Author:** ![nickvergessen](https://help.nextcloud.com/user_avatar/help.nextcloud.com/nickvergessen/32/66965_2.png) [@nickvergessen](https://help.nextcloud.com/u/nickvergessen)\
**Post date:** [November 16, 2020, 4:43pm UTC](https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289/3 "2020-11-16T16:43:46Z")

</div>

> # Resolution
> 
> It is recommended that the Nextcloud Server is upgraded to 20.0.0.

The resolution (for any version) is to update to 20.0.0 or later

---

<div class="post-metadata">

**Author:** ![lcts](https://help.nextcloud.com/user_avatar/help.nextcloud.com/lcts/32/32174_2.png) [@lcts](https://help.nextcloud.com/u/lcts)\
**Post date:** [November 16, 2020, 4:58pm UTC](https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289/4 "2020-11-16T16:58:40Z")

</div>

OK. Thanks for the clarification. Bit weird for a _supported_ version to not receive _security_ fixes, but I see from the related PR that the fix is non-trivial.

---

<div class="post-metadata">

**Author:** ![Thom1](https://help.nextcloud.com/user_avatar/help.nextcloud.com/thom1/32/43669_2.png) [@Thom1](https://help.nextcloud.com/u/Thom1)\
**Post date:** [November 16, 2020, 5:25pm UTC](https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289/5 "2020-11-16T17:25:33Z")

</div>

Hi,

Do you mean all supported version (except 20.0) won’t be fixed?

---

<div class="post-metadata">

**Author:** ![nickvergessen](https://help.nextcloud.com/user_avatar/help.nextcloud.com/nickvergessen/32/66965_2.png) [@nickvergessen](https://help.nextcloud.com/u/nickvergessen)\
**Post date:** [November 16, 2020, 5:50pm UTC](https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289/6 "2020-11-16T17:50:59Z")

</div>

Exactly. Looking at the attack vector of the issue and the size/dimension of the fix, we agreed that it is acceptable to have “Update to 20” as a resolution.

---

<div class="post-metadata">

**Author:** ![Thom1](https://help.nextcloud.com/user_avatar/help.nextcloud.com/thom1/32/43669_2.png) [@Thom1](https://help.nextcloud.com/u/Thom1)\
**Post date:** [November 16, 2020, 5:58pm UTC](https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289/7 "2020-11-16T17:58:38Z")

</div>

Thanks to answer quickly.  
This attack affects only installation with encrypted files?
