Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Mejo-

#47922of 53,624
5.3Total CVSS
Vulnerabilities · 1
PT-2022-11377
5.3
2022-03-08
Nextcloud · Nextcloud Server · CVE-2021-41239
**Name of the Vulnerable Software and Affected Versions** Nextcloud Server versions prior to 20.0.14 Nextcloud Server versions prior to 21.0.6 Nextcloud Server versions prior to 22.2.1 **Description** The Nextcloud server is a self-hosted system designed to provide cloud-style services. In affected versions, the User Status API did not consider the user enumeration settings set by the administrator. This allowed a user to enumerate other users on the instance, even when user listings were disabled. **Recommendations** For versions prior to 20.0.14, upgrade to 20.0.14. For versions prior to 21.0.6, upgrade to 21.0.6. For versions prior to 22.2.1, upgrade to 22.2.1. As a temporary workaround, consider disabling the User Status API until a patch is available.