CVE-2021-41178
Last modified
CVE-2021-41178 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. EPSS estimates a 1.73% chance of exploitation in the next 30 days.
Description
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged into a XSS/phishing attack, an attacker could upload a malicious SVG file that mimics the Nextcloud login form and send a specially crafted link to victims. The XSS risk here is mitigated due to the fact that Nextcloud employs a strict Content-Security-Policy disallowing execution of arbitrary JavaScript. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5 or 22.2.0. There are no known workarounds aside from upgrading.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Server | >= 20.0.3, < 20.0.13 |
| Nextcloud | Server | >= 21.0.1, < 21.0.5 |
| Nextcloud | Server | >= 22.1.1, < 22.2.0 |
References
- https://github.com/nextcloud/server/pull/28726Patch, Third Party Advisory
- https://hackerone.com/reports/1302155Permissions Required
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
- https://github.com/nextcloud/server/pull/28726Patch, Third Party Advisory
- https://hackerone.com/reports/1302155Permissions Required
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-41178?
How severe is CVE-2021-41178?
How do I fix CVE-2021-41178?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-41172AS_Redis is an AntSword plugin for Redis. The Redis Manage p…5.4
- CVE-2021-41173Go Ethereum is the official Golang implementation of the Eth…5.7
- CVE-2021-41174Grafana is an open-source platform for monitoring and observ…6.1
- CVE-2021-41175Pi-hole's Web interface (based on AdminLTE) provides a centr…5.4
- CVE-2021-41176Pterodactyl is an open-source game server management panel b…4.3
- CVE-2021-41177Nextcloud is an open-source, self-hosted productivity platfo…8.1
- CVE-2021-41179Nextcloud is an open-source, self-hosted productivity platfo…6.5
- CVE-2021-4118pytorch-lightning is vulnerable to Deserialization of Untrus…7.8
- CVE-2021-41180Nextcloud talk is a self hosting messaging service. In versi…6.1
- CVE-2021-41181Nextcloud talk is a self hosting messaging service. In versi…2.4
- CVE-2021-41182jQuery-UI is the official jQuery user interface library. Pri…6.1
- CVE-2021-41183jQuery-UI is the official jQuery user interface library. Pri…6.1
Are you affected by CVE-2021-41178?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
