Related Vulnerabilities: CVE-2021-32653  

Nextcloud Server before version 21.0.2 sends user IDs to the lookup server even if the user has no fields set to be published.

Severity Low

Remote Yes

Type Information disclosure

Description

Nextcloud Server before version 21.0.2 sends user IDs to the lookup server even if the user has no fields set to be published.

AVG-2024 nextcloud 21.0.1-3 21.0.2-1 High Fixed

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-396j-vqpr-qg45
https://hackerone.com/reports/1173436