PT-2021-22474 · Nextcloud · Nextcloud Richdocuments

Lukas Reschke

·

Published

2021-10-25

·

Updated

2021-10-29

·

CVE-2021-39223

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Richdocuments versions prior to 3.8.6 and 4.2.3
Description The Nextcloud Richdocuments application returned verbatim exception messages to the user, which could result in a full path disclosure on shared files. For example, an attacker could see that the file shared.txt is located within /files/$username/Myfolder/Mysubfolder/shared.txt.
Recommendations For versions prior to 3.8.6, upgrade to version 3.8.6. For versions prior to 4.2.3, upgrade to version 4.2.3. As a temporary workaround, consider disabling the Richdocuments application in the app settings.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39223
GHSA-RJCC-4CGJ-6V93

Affected Products

Nextcloud Richdocuments