CVE-2021-41241 Information
Description
Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition it allows setting dvanced permissions\ on subfolders for example a user could be granted access to the groupfolder but not specific subfolders. Due to a lacking permission check in affected versions a user could still access these subfolders by copying the groupfolder to another location. It is recommended that the Nextcloud Server is upgraded to 20.0.14 21.0.6 or 22.2.1. Users unable to upgrade should disable the \groupfolders\ application in the admin settings.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Reference
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m4wp-r357-4q94 https://github.com/nextcloud/server/pull/29362 https://github.com/nextcloud/groupfolders/issues/1692
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
LOW
Availability Impact
NONE
Base Score
NONE
Base Severity
4.3
Share on: