Description


Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

Related CPE's


a

nextcloud

nextcloud_server

3

Weaknesses



CWE-799


NVD-CWE-Other

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

5.3 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2021-07-12T20:15:07.993Z

4 years ago

Last modified

2024-11-21T05:07:39.033Z

1 year ago