CVE-2021-32680 Information

Description

Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13 20.0.11 and 21.0.3 Nextcloud Server audit logging functionality wasn’t properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13 20.0.11 and 21.0.3.

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Reference

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fxpq-wq7c-vppf https://hackerone.com/reports/1200810 https://github.com/nextcloud/server/pull/27024 https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/J63NBVPR2AQCAWRNDOZSGRY5II4WS2CZ/ https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/BVZS26RDME2DYTKET5AECRIZDFUGR2AZ/

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

3.3

Share on: