forked from mirrors/nixpkgs
520b10453f
ChangeLogs: * https://nextcloud.com/changelog/#20-0-3 * https://nextcloud.com/changelog/#19-0-6 For Nextcloud 20, security advisories for CVE-2020-8259[1] & CVE-2020-8152[2] were published. The only way to fix those is to upgrade to v20, although v19 and v18 are supported, the issue won't be fixed there[3]. Even though both CVEs are only related to the encryption module[4] which is turned off by default, I decided to add a vulnerability note to `nextcloud19` since CVE-2020-8259's is rated as "High" by NIST (in contrast to Nextcloud which rates it as "Low"). If one is not affected by the issue, `nextcloud19` can still be used by declaring `permittedInsecurePackages`[5]. [1] https://nvd.nist.gov/vuln/detail/CVE-2020-8259, https://nextcloud.com/security/advisory/?id=NC-SA-2020-041 [2] https://nvd.nist.gov/vuln/detail/CVE-2020-8152, https://nextcloud.com/security/advisory/?id=NC-SA-2020-040 [3] https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289 [4] https://docs.nextcloud.com/server/20/admin_manual/configuration_files/encryption_configuration.html [5] https://nixos.org/manual/nixpkgs/stable/#sec-allow-insecure Closes #106212 |
||
---|---|---|
.. | ||
adguardhome | ||
adminer | ||
amqp | ||
ankisyncd | ||
apache-kafka | ||
apcupsd | ||
asterisk | ||
atlassian | ||
bazarr | ||
beanstalkd | ||
bird | ||
blockbook | ||
brickd | ||
caddy | ||
cayley | ||
clickhouse | ||
cloud-print-connector | ||
code-server | ||
computing | ||
confluent-platform | ||
consul | ||
corosync | ||
coturn | ||
couchpotato | ||
dante | ||
demoit | ||
dex | ||
dgraph | ||
dico | ||
dict | ||
diod | ||
dns | ||
documize-community | ||
domoticz | ||
echoip | ||
elasticmq | ||
elasticmq-server-bin | ||
endlessh | ||
etcd | ||
exhibitor | ||
fcgiwrap | ||
felix | ||
fileshare | ||
fingerd/bsd-fingerd | ||
firebird | ||
foundationdb | ||
freeradius | ||
ftp | ||
gemini/molly-brown | ||
gerbera | ||
go-libp2p-daemon | ||
gobetween | ||
gonic | ||
gopher/gofish | ||
gortr | ||
gotify | ||
gotty | ||
gpm | ||
gpsd | ||
grocy | ||
h2 | ||
hashi-ui | ||
hasura | ||
hbase | ||
headphones | ||
hitch | ||
holochain-go | ||
home-assistant | ||
http | ||
hydron | ||
hylafaxplus | ||
icecast | ||
icingaweb2 | ||
identd | ||
imgproxy | ||
interlock | ||
irc | ||
irker | ||
isso | ||
jackett | ||
jellyfin | ||
jetbrains | ||
jicofo | ||
jitsi-videobridge | ||
kapowbang | ||
keycloak | ||
kippo | ||
klipper | ||
kwakd | ||
ldap/389 | ||
lidarr | ||
limesurvey | ||
livepeer | ||
ma1sd | ||
martin | ||
matrix-appservice-discord | ||
matrix-synapse | ||
matterbridge | ||
mattermost | ||
mautrix-telegram | ||
mautrix-whatsapp | ||
mbtileserver | ||
mediatomb | ||
memcached | ||
mesos-dns | ||
metabase | ||
meteor | ||
microserver | ||
miniflux | ||
minio | ||
mirrorbits | ||
misc | ||
mlflow-server | ||
monitoring | ||
mpd | ||
mqtt/mosquitto | ||
mtprotoproxy | ||
mumsi | ||
mxisd | ||
nas | ||
nats-server | ||
nats-streaming-server | ||
neard | ||
news/leafnode | ||
nextcloud | ||
nfs-ganesha | ||
nginx-sso | ||
nosql | ||
nsq | ||
oauth2_proxy | ||
openafs | ||
openbgpd | ||
openxpki | ||
osrm-backend | ||
p910nd | ||
peach | ||
pg_featureserv | ||
pg_tileserv | ||
pies | ||
pim6sd | ||
pinnwand | ||
plex | ||
polipo | ||
pounce | ||
prayer | ||
ps3netsrv | ||
pulseaudio | ||
quagga | ||
radarr | ||
radicale | ||
rainloop | ||
rippled | ||
roon-server | ||
roundcube | ||
routinator | ||
rpcbind | ||
rt | ||
rtsp-simple-server | ||
sabnzbd | ||
samba | ||
scylladb | ||
search | ||
ser2net | ||
serf | ||
serviio | ||
shairplay | ||
shairport-sync | ||
shellinabox | ||
shishi | ||
sickbeard | ||
silc-server | ||
simplehttp2server | ||
sip | ||
sks | ||
skydns | ||
slimserver | ||
smcroute | ||
softether | ||
sonarr | ||
sozu | ||
sql | ||
squid | ||
sslh | ||
syncserver | ||
tacacsplus | ||
tailscale | ||
tang | ||
tarssh | ||
tautulli | ||
tegola | ||
teleport | ||
tmate-ssh-server | ||
tracing/tempo | ||
traefik | ||
trezord | ||
trickster | ||
tt-rss | ||
ttyd | ||
tvheadend | ||
u9fs | ||
udpt | ||
uftp | ||
uhub | ||
ums | ||
unfs3 | ||
unifi | ||
unpfs | ||
ursadb | ||
urserver | ||
uwsgi | ||
varnish | ||
web-apps | ||
webmetro | ||
wsdd | ||
x11 | ||
xandikos | ||
xinetd | ||
xmpp | ||
zigbee2mqtt | ||
zoneminder | ||
zookeeper |