Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud Text 存在安全漏洞,该漏洞源于在受影响的版本中,Nextcloud Text 应用程序返回不同的错误消息,具体取决于公共链接共享中是否存在文件夹。如果公共链接共享是使用“仅上传”权限创建的,则这是有问题的。 (又名“文件删除”)。链接共享收件人不会看到“文件放置”共享中存在哪些文件夹或文件。使用此漏洞,攻击者能够枚举此类共享中的文件夹。漏洞利用要求攻击者有权访问有效的受影响的“文件删除”
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 20.0.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32802 | 9.3 CRITICAL | Preview generation used third-party library not suited for user-generated content in Nextc |
| CVE-2021-32800 | 8.1 HIGH | Bypass of Two Factor Authentication in Nextcloud server |
| CVE-2021-37628 | 7.5 HIGH | File Drop can be bypassed using Richdocuments app in nextcloud |
| CVE-2021-37630 | 6.5 MEDIUM | Secret Circle can be joined without approval in Nextcloud Circles |
| CVE-2021-37631 | 6.5 MEDIUM | Circle can be accessed by non-Circle members in Nextcloud Deck |
| CVE-2021-32782 | 5.8 MEDIUM | Cross-Site Scripting in Nextcloud Circles |
| CVE-2021-32801 | 5.5 MEDIUM | Exceptions may have logged Encryption-at-Rest key content in Nextcloud server |
| CVE-2021-37629 | 5.3 MEDIUM | Lack of ratelimit on Richdocuments OCS endpoint in nextcloud |
No comments yet