PT-2021-21744 · Nextcloud · Nextcloud Richdocuments

Lukasreschke

·

Published

2021-09-07

·

Updated

2021-09-14

·

CVE-2021-37629

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Richdocuments versions prior to 3.8.4 Nextcloud Richdocuments versions prior to 4.2.1
Description Nextcloud Richdocuments is an open source collaborative office suite. In affected versions, there is a lack of rate limiting on the "Richdocuments OCS endpoint". This may have allowed an attacker to enumerate potentially valid share tokens.
Recommendations For versions prior to 3.8.4, upgrade to version 3.8.4 to resolve the issue. For versions prior to 4.2.1, upgrade to version 4.2.1 to resolve the issue. For users unable to upgrade, disable the Richdocuments application as a temporary workaround.

Fix

Information Disclosure

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37629
GHSA-GVVR-H36P-8MJX

Affected Products

Nextcloud Richdocuments