TLS Host Verification Bypass in Nextcloud Mail 1.1.3: Enabling Man-in-the-Middle Attacks

TLS Host Verification Bypass in Nextcloud Mail 1.1.3: Enabling Man-in-the-Middle Attacks

CVE-2020-8156 · HIGH Severity

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:L

A missing verification of the TLS host in Nextcloud Mail 1.1.3 allowed a man in the middle attack.

Learn more about our Cloud Audit.