Description


Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

Related CPE's


a

nextcloud

nextcloud_server

3

Weaknesses



CWE-708


CWE-287

CVSS impact metrics


CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

7.1 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-07-12T18:15:10.037Z

4 years ago

Last modified

2024-11-21T05:07:36.587Z

1 year ago