CVE-2021-32726 Information
Jun 07, 2022
cve
Description
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13 20.011 and 21.0.3 webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username the previous user could gain access to their account. The issue was fixed in versions 19.0.13 20.0.11 and 21.0.3. There are no known workarounds.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://hackerone.com/reports/1202590 https://github.com/nextcloud/server/pull/27532 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6qr9-c846-j8mg
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: