PT-2021-19915 · Nextcloud+2 · Nextcloud Server+3

Lukas Reschke

·

Published

2021-09-07

·

Updated

2022-09-27

·

CVE-2021-32766

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server versions prior to 20.0.12 Nextcloud Server versions prior to 21.0.4 Nextcloud Server versions prior to 22.0.1
Description The Nextcloud Text application, which ships with the Nextcloud Server, returns different error messages depending on whether a folder exists in a public link share. This is problematic when the public link share has been created with "Upload Only" privileges, also known as "File Drop". A link share recipient should not be able to see which folders or files exist in a "File Drop" share. An attacker can exploit this issue to enumerate folders in such a share, but they must have access to a valid affected "File Drop" link share.
Recommendations For Nextcloud Server versions prior to 20.0.12, upgrade to version 20.0.12. For Nextcloud Server versions prior to 21.0.4, upgrade to version 21.0.4. For Nextcloud Server versions prior to 22.0.1, upgrade to version 22.0.1. If an upgrade is not possible, disable the Nextcloud Text application in the app settings as a temporary workaround.

Fix

Generation of Error Message Containing Sensitive Information

Weakness Enumeration

Related Identifiers

ALT-PU-2021-3108
ALT-PU-2021-3224
CVE-2021-32766
GHSA-GCF3-3WMC-88JR
OPENSUSE-SU-2021:1250-1
OPENSUSE-SU-2021:1252-1
OPENSUSE-SU-2021:1253-1
OPENSUSE-SU-2021:1255-1
OPENSUSE-SU-2021:1275-1
OPENSUSE-SU-2021_1253-1

Affected Products

Alt Linux
Nextcloud Server
Nextcloud Text
Suse