CVE-2021-32688
Last modified
CVE-2021-32688 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. EPSS estimates a 2.31% chance of exploitation in the next 30 days.
Description
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, the tokens were able to change their own permissions in versions prior to 19.0.13, 20.0.11, and 21.0.3. Thus fileystem limited tokens were able to grant themselves access to the filesystem. The issue is patched in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds aside from upgrading.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud Server | < 19.0.13 |
| Nextcloud | Nextcloud Server | >= 20.0.0, < 20.0.11 |
| Nextcloud | Nextcloud Server | >= 21.0.0, < 21.0.3 |
| Fedoraproject | Fedora | 33 |
| Fedoraproject | Fedora | 34 |
References
- https://github.com/nextcloud/server/pull/27000Patch, Third Party Advisory
- https://hackerone.com/reports/1193321Permissions Required
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
- https://github.com/nextcloud/server/pull/27000Patch, Third Party Advisory
- https://hackerone.com/reports/1193321Permissions Required
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-32688?
How severe is CVE-2021-32688?
How do I fix CVE-2021-32688?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-32682elFinder is an open-source file manager for web, written in …9.8
- CVE-2021-32683wire-webapp is the web version of Wire, an open-source messe…6.1
- CVE-2021-32684magento-scripts contains scripts and configuration used by C…5.5
- CVE-2021-32685tEnvoy contains the PGP, NaCl, and PBKDF2 in node.js and the…9.8
- CVE-2021-32686PJSIP is a free and open source multimedia communication lib…5.9
- CVE-2021-32687Redis is an open source, in-memory database that persists on…7.5
- CVE-2021-32689Nextcloud Talk is a fully on-premises audio/video and chat c…6.5
- CVE-2021-32690Helm is a tool for managing Charts (packages of pre-configur…8.6
- CVE-2021-32691Apollos Apps is an open source platform for launching church…9.8
- CVE-2021-32692Activity Watch is a free and open-source automated time trac…9.6
- CVE-2021-32693Symfony is a PHP framework for web and console applications …8.8
- CVE-2021-32694Nextcloud Android app is the Android client for Nextcloud. I…5.5
Are you affected by CVE-2021-32688?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
