Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud server存在日志信息泄露漏洞,该漏洞源于在受影响的版本中,记录异常可能会导致为Nextcloud rest加密功能记录潜在敏感的关键材料。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 20.0.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32802 | 9.3 CRITICAL | Preview generation used third-party library not suited for user-generated content in Nextc |
| CVE-2021-32800 | 8.1 HIGH | Bypass of Two Factor Authentication in Nextcloud server |
| CVE-2021-37628 | 7.5 HIGH | File Drop can be bypassed using Richdocuments app in nextcloud |
| CVE-2021-37630 | 6.5 MEDIUM | Secret Circle can be joined without approval in Nextcloud Circles |
| CVE-2021-37631 | 6.5 MEDIUM | Circle can be accessed by non-Circle members in Nextcloud Deck |
| CVE-2021-32782 | 5.8 MEDIUM | Cross-Site Scripting in Nextcloud Circles |
| CVE-2021-32766 | 5.3 MEDIUM | Nextcloud Text app can disclose existence of folders in "File Drop" link share |
| CVE-2021-37629 | 5.3 MEDIUM | Lack of ratelimit on Richdocuments OCS endpoint in nextcloud |
No comments yet