CVE-2021-41239 Information
Jun 07, 2022
cve
Description
Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance even when user listings where disabled. It is recommended that the Nextcloud Server is upgraded to 20.0.14 21.0.6 or 22.2.1. There are no known workarounds.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Reference
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g722-cm3h-8wrx https://github.com/nextcloud/server/pull/29260 https://github.com/nextcloud/server/issues/27122
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
5.3
Share on: