Vulnerability Name:

CVE-2021-32766 (CCN-208903)

Assigned:2021-09-06
Published:2021-09-06
Updated:2022-09-27
Summary:Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder existed in a public link share. This is problematic in case the public link share has been created with "Upload Only" privileges. (aka "File Drop"). A link share recipient is not expected to see which folders or files exist in a "File Drop" share. Using this vulnerability an attacker is able to enumerate folders in such a share. Exploitation requires that the attacker has access to a valid affected "File Drop" link share. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.0.1. Users who are unable to upgrade are advised to disable the Nextcloud Text application in the app settings.
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-209
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-32766

Source: XF
Type: UNKNOWN
nextcloud-cve202132766-info-disc(208903)

Source: CCN
Type: Nextcloud GIT Repository
Nextcloud Text app can disclose existence of folders in "File Drop" link share

Source: CONFIRM
Type: Third Party Advisory
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-gcf3-3wmc-88jr

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/nextcloud/text/pull/1716

Source: MISC
Type: Permissions Required, Third Party Advisory
https://hackerone.com/reports/1253475

Vulnerable Configuration:Configuration 1:
  • cpe:/a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* (Version >= 21.0.0 and < 21.0.4)
  • OR cpe:/a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* (Version >= 22.0.0 and < 22.1.0)
  • OR cpe:/a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* (Version < 20.0.12)

  • Configuration CCN 1:
  • cpe:/a:nextcloud:nextcloud_server:20.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:nextcloud:nextcloud_server:21.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:nextcloud:nextcloud_server:22.0.0:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:93638
    P
    (Important)
    2022-03-10
    oval:org.opensuse.security:def:100351
    P
    (Important)
    2021-11-16
    oval:org.opensuse.security:def:11131
    P
    Security update for nextcloud (Important)
    2021-09-16
    oval:org.opensuse.security:def:103115
    P
    Security update for nextcloud (Important)
    2021-09-16
    oval:org.opensuse.security:def:96425
    P
    Security update for nextcloud (Important)
    2021-09-16
    oval:org.opensuse.security:def:109772
    P
    Security update for nextcloud (Important)
    2021-09-16
    oval:org.opensuse.security:def:111055
    P
    Security update for nextcloud (Important)
    2021-09-14
    oval:org.opensuse.security:def:35510
    P
    Security update for nextcloud (Important)
    2021-09-14
    oval:org.opensuse.security:def:111502
    P
    Security update for nextcloud (Important)
    2021-09-14
    oval:org.opensuse.security:def:11129
    P
    Security update for nextcloud (Important)
    2021-09-14
    oval:org.opensuse.security:def:11128
    P
    Security update for nextcloud (Important)
    2021-09-13
    oval:org.opensuse.security:def:107017
    P
    Security update for nextcloud (Important)
    2021-09-13
    BACK
    nextcloud nextcloud server *
    nextcloud nextcloud server *
    nextcloud nextcloud server *
    nextcloud nextcloud server 20.0.0
    nextcloud nextcloud server 21.0.0 -
    nextcloud nextcloud server 22.0.0 -