Una libreria 3rd party superata nel visualizzatore di file PDF per Nextcloud Server 18.0.2 ha provocato una vulnerabilità Cross-site scripting quando si apre un PDF dannoso.
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KC6HLX5SG4PZO6Y54D2LFJ4ATG76BKOP/
https://nextcloud.com/security/advisory/?id=NC-SA-2020-019
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00037.html
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00038.html
http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00040.html
http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00019.html
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8155