Vulnerability Name: | CVE-2021-32653 (CCN-202831) | ||||||||||||
Assigned: | 2021-06-01 | ||||||||||||
Published: | 2021-06-01 | ||||||||||||
Updated: | 2022-10-26 | ||||||||||||
Summary: | Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, or 21.0.2 send user IDs to the lookup server even if the user has no fields set to published. The vulnerability is patched in versions 19.0.11, 20.0.10, and 21.0.2; no workarounds outside the updates are known to exist. | ||||||||||||
CVSS v3 Severity: | 2.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N) 2.4 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-201 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-32653 Source: XF Type: UNKNOWN nextcloud-cve202132653-info-disc(202831) Source: CCN Type: Nextcloud GIT Repository Default settings leak federated cloud ID to lookup server of all users Source: CONFIRM Type: Third Party Advisory https://github.com/nextcloud/security-advisories/security/advisories/GHSA-396j-vqpr-qg45 Source: MISC Type: Permissions Required, Third Party Advisory https://hackerone.com/reports/1173436 Source: GENTOO Type: Third Party Advisory GLSA-202208-17 | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |