nixpkgs/pkgs
Maximilian Bosch 520b10453f
nextcloud: 19.0.4 -> 19.0.6, 20.0.1 -> 20.0.3, mark v19 as insecure
ChangeLogs:

* https://nextcloud.com/changelog/#20-0-3
* https://nextcloud.com/changelog/#19-0-6

For Nextcloud 20, security advisories for CVE-2020-8259[1] &
CVE-2020-8152[2] were published. The only way to fix those is to upgrade
to v20, although v19 and v18 are supported, the issue won't be fixed
there[3].

Even though both CVEs are only related to the encryption module[4] which
is turned off by default, I decided to add a vulnerability note to
`nextcloud19` since CVE-2020-8259's is rated as "High" by NIST (in
contrast to Nextcloud which rates it as "Low").

If one is not affected by the issue, `nextcloud19` can still be used by
declaring `permittedInsecurePackages`[5].

[1] https://nvd.nist.gov/vuln/detail/CVE-2020-8259,
    https://nextcloud.com/security/advisory/?id=NC-SA-2020-041
[2] https://nvd.nist.gov/vuln/detail/CVE-2020-8152,
    https://nextcloud.com/security/advisory/?id=NC-SA-2020-040
[3] https://help.nextcloud.com/t/fixes-for-cve-2020-8259-cve-2020-8152-in-nextcloud-18-19/98289
[4] https://docs.nextcloud.com/server/20/admin_manual/configuration_files/encryption_configuration.html
[5] https://nixos.org/manual/nixpkgs/stable/#sec-allow-insecure

Closes #106212
2020-12-11 12:39:57 +01:00
..
applications chromiumBeta: 88.0.4324.27 -> 88.0.4324.41 2020-12-10 17:43:52 +01:00
build-support Merge pull request #106409 from jonringer/fix-steam 2020-12-09 17:08:05 +01:00
common-updater
data Merge pull request #106280 from r-ryantm/auto-update/iosevka-bin 2020-12-08 03:57:03 -05:00
desktops Merge pull request #106396 from InternetUnexplorer/fix/plasma-workspace-use-qqc2-style 2020-12-09 15:35:31 -06:00
development geant4: 10.6.3 -> 10.7.0 (#105920) 2020-12-10 12:33:29 -05:00
games Merge pull request #106409 from jonringer/fix-steam 2020-12-09 17:08:05 +01:00
misc melonDS: 0.8.3 -> 0.9 (and build fix) (#106489) 2020-12-09 17:58:10 -05:00
os-specific linux-rt_5_9: export symbols needed by zfs 2020-12-10 10:34:44 +00:00
pkgs-lib
servers nextcloud: 19.0.4 -> 19.0.6, 20.0.1 -> 20.0.3, mark v19 as insecure 2020-12-11 12:39:57 +01:00
shells Remove myself from maintainers sets 2020-12-07 14:30:37 +00:00
stdenv Merge master into staging-next 2020-12-03 00:36:28 +00:00
test
tools Merge pull request #106488 from Luflosi/update/youtube-dl 2020-12-10 17:57:22 +01:00
top-level Merge pull request #106534 from orivej/zfs-rt 2020-12-10 15:10:30 +00:00