CVE Vulnerabilities

CVE-2021-32655

Published: Jun 01, 2021 | Modified: Oct 26, 2022
CVSS 3.x
3.5
LOW
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.11, 20.0.10, and 21.0.2, an attacker is able to convert a Files Drop link to a federated share. This causes an issue on the UI side of the sharing user. When the sharing user opens the sharing panel and tries to remove the Create privileges of this unexpected share, Nextcloud server would silently grant the share read privileges. The vulnerability is patched in versions 19.0.11, 20.0.10 and 21.0.2. No workarounds are known to exist.

Affected Software

Name Vendor Start Version End Version
Nextcloud_server Nextcloud * 19.0.11 (excluding)
Nextcloud_server Nextcloud 20.0.0 (including) 20.0.10 (excluding)
Nextcloud_server Nextcloud 21.0.0 (including) 21.0.2 (excluding)

References