CVE-2021-32725 Information
Jun 07, 2022
cve
Description
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13 20.011 and 21.0.3 default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13 20.0.11 and 21.0.3. There are no known workarounds.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6f6v-h9x9-jj4v https://github.com/nextcloud/server/pull/26946 https://hackerone.com/reports/1178320
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: