Vulnerability Name:

CVE-2021-41179 (CCN-211972)

Assigned:2021-10-25
Published:2021-10-25
Updated:2021-10-29
Summary:Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and 22.2.0, the Two-Factor Authentication wasn't enforced for pages marked as public. Any page marked as `@PublicPage` could thus be accessed with a valid user session that isn't authenticated. This particularly affects the Nextcloud Talk application, as this could be leveraged to gain access to any private chat channel without going through the Two-Factor flow. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5 or 22.2.0. There are no known workarounds aside from upgrading.
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
8.1 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N)
7.1 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
8.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:C/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): None
Vulnerability Type:CWE-304
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2021-41179

Source: XF
Type: UNKNOWN
nextcloud-cve202141179-sec-bypass(211972)

Source: CCN
Type: Nextcloud GIT Repository
Two-Factor Authentication not enforced for pages marked as public

Source: CONFIRM
Type: Third Party Advisory
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7hvh-rc6f-px23

Source: MISC
Type: Patch, Third Party Advisory
https://github.com/nextcloud/server/pull/28725

Source: MISC
Type: Permissions Required
https://hackerone.com/reports/1322865

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2021-41179

Vulnerable Configuration:Configuration 1:
  • cpe:/a:nextcloud:server:*:*:*:*:*:*:*:* (Version >= 20.0.3 and < 20.0.13)
  • OR cpe:/a:nextcloud:server:*:*:*:*:*:*:*:* (Version >= 21.0.1 and < 21.0.5)
  • OR cpe:/a:nextcloud:server:*:*:*:*:*:*:*:* (Version >= 22.1.1 and < 22.2.0)

  • Configuration CCN 1:
  • cpe:/a:nextcloud:nextcloud_server:20.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:nextcloud:nextcloud_server:21.0.0:-:*:*:*:*:*:*
  • OR cpe:/a:nextcloud:nextcloud_server:22.1.0:-:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:96437
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:111176
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:35512
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:100357
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:111525
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:11160
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:103127
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:107023
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:93644
    P
    Security update for nextcloud (Important)
    2021-12-20
    oval:org.opensuse.security:def:109784
    P
    Security update for nextcloud (Important)
    2021-12-20
    BACK
    nextcloud server *
    nextcloud server *
    nextcloud server *
    nextcloud nextcloud server 20.0.0
    nextcloud nextcloud server 21.0.0 -
    nextcloud nextcloud server 22.1.0 -