PT-2021-21744 · Nextcloud · Nextcloud Richdocuments
Lukasreschke
·
Published
2021-09-07
·
Updated
2021-09-14
·
CVE-2021-37629
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Richdocuments versions prior to 3.8.4
Nextcloud Richdocuments versions prior to 4.2.1
Description
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions, there is a lack of rate limiting on the "Richdocuments OCS endpoint". This may have allowed an attacker to enumerate potentially valid share tokens.
Recommendations
For versions prior to 3.8.4, upgrade to version 3.8.4 to resolve the issue.
For versions prior to 4.2.1, upgrade to version 4.2.1 to resolve the issue.
For users unable to upgrade, disable the Richdocuments application as a temporary workaround.
Fix
Information Disclosure
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Richdocuments