8.8
CVSSv3

CVE-2021-32688

Published: 12/07/2021 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, the tokens were able to change their own permissions in versions before 19.0.13, 20.0.11, and 21.0.3. Thus fileystem limited tokens were able to grant themselves access to the filesystem. The issue is patched in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds aside from upgrading.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nextcloud nextcloud server

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Nextcloud Server supports application specific tokens for authentication purposes These tokens are supposed to be granted to a specific applications (eg DAV sync clients), and can also be configured by the user to not have any filesystem access Due to a lacking permission check, the tokens were able to change their own permissions in versions p ...