PT-2021-21743 · Nextcloud · Nextcloud Richdocuments

Lukas Reschke

·

Published

2021-09-07

·

Updated

2021-09-14

·

CVE-2021-37628

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Richdocuments versions prior to 3.8.4 Nextcloud Richdocuments versions prior to 4.2.1
Description The File Drop feature in Nextcloud Richdocuments can be bypassed, allowing an attacker to read arbitrary files in a shared folder. This issue affects the "Upload Only" public link shares in Nextcloud when using the Nextcloud Richdocuments app.
Recommendations For versions prior to 3.8.4, upgrade to version 3.8.4. For versions prior to 4.2.1, upgrade to version 4.2.1. If upgrading is not possible, disable the Richdocuments application as a temporary workaround.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37628
GHSA-PXHH-954F-8W7W

Affected Products

Nextcloud Richdocuments