PT-2021-19832 · Nextcloud+1 · Nextcloud Server+1

Rtod

·

Published

2021-06-01

·

Updated

2022-10-26

·

CVE-2021-32654

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server versions prior to 19.0.11 Nextcloud Server versions prior to 20.0.10 Nextcloud Server versions prior to 21.0.2
Description The issue allows an attacker to gain write/read privileges on any Federated File Share. This can also be exploited on any public link, as public links can be added as a federated file share.
Recommendations For versions prior to 19.0.11, upgrade to version 19.0.11 or disable federated file sharing as a workaround. For versions prior to 20.0.10, upgrade to version 20.0.10 or disable federated file sharing as a workaround. For versions prior to 21.0.2, upgrade to version 21.0.2 or disable federated file sharing as a workaround.

Fix

IDOR

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3108
ALT-PU-2021-3224
CVE-2021-32654
GHSA-JF9H-V24C-22G5

Affected Products

Alt Linux
Nextcloud Server