CVE-2021-32800 Information
Jun 07, 2022
cve
Description
Nextcloud server is an open source self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a password or access to a WebAuthN trusted device of a user was sufficient to gain access to an account. It is recommended that the Nextcloud Server is upgraded to 20.0.12 21.0.4 or 22.1.0. There are no workaround for this vulnerability.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Reference
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-gv5w-8q25-785v https://hackerone.com/reports/1271052 https://github.com/nextcloud/server/pull/28078
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
NONE
Base Severity
8.1
Share on: