CVE-2021-32653
Last modified
CVE-2021-32653 is a low-severity vulnerability rated 2.7/10 on the CVSS scale. Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, or 21.0.2 send user IDs to the lookup server even if the user has no fields set to published. EPSS estimates a 1.21% chance of exploitation in the next 30 days.
Description
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, or 21.0.2 send user IDs to the lookup server even if the user has no fields set to published. The vulnerability is patched in versions 19.0.11, 20.0.10, and 21.0.2; no workarounds outside the updates are known to exist.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud Server | < 19.0.11 |
| Nextcloud | Nextcloud Server | >= 20.0.0, < 20.0.10 |
| Nextcloud | Nextcloud Server | >= 21.0.0, < 21.0.2 |
References
- https://hackerone.com/reports/1173436Permissions Required, Third Party Advisory
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
- https://hackerone.com/reports/1173436Permissions Required, Third Party Advisory
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32653?
How severe is CVE-2021-32653?
How do I fix CVE-2021-32653?
Are you affected by CVE-2021-32653?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
