CVE-2021-32654 Information
Jun 07, 2022
cve
Description
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11 20.0.10 and 21.0.2 an attacker is able to receive write/read privileges on any Federated File Share. Since public links can be added as federated file share this can also be exploited on any public link. Users can upgrade to patched versions (19.0.11 20.0.10 or 21.0.2) or as a workaround disable federated file sharing.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Reference
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jf9h-v24c-22g5 https://hackerone.com/reports/1170024
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
9.1
Share on: