Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud Richdocuments存在信息泄露漏洞,该漏洞源于在受影响的版本中,Richdocuments OCS端点没有速率限制。这可能允许攻击者可利用该漏洞枚举潜在的有效共享令牌。建议将Nextcloud Richdocuments应用升级到3.8.4或4.2.1来解决。对于无法升级的用户,建议禁用Richdocuments应用程序。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 3.8.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32802 | 9.3 CRITICAL | Preview generation used third-party library not suited for user-generated content in Nextc |
| CVE-2021-32800 | 8.1 HIGH | Bypass of Two Factor Authentication in Nextcloud server |
| CVE-2021-37630 | 6.5 MEDIUM | Secret Circle can be joined without approval in Nextcloud Circles |
| CVE-2021-37631 | 6.5 MEDIUM | Circle can be accessed by non-Circle members in Nextcloud Deck |
| CVE-2021-32782 | 5.8 MEDIUM | Cross-Site Scripting in Nextcloud Circles |
| CVE-2021-32801 | 5.5 MEDIUM | Exceptions may have logged Encryption-at-Rest key content in Nextcloud server |
| CVE-2021-32766 | 5.3 MEDIUM | Nextcloud Text app can disclose existence of folders in "File Drop" link share |
| CVE-2021-37629 | 5.3 MEDIUM | Lack of ratelimit on Richdocuments OCS endpoint in nextcloud |
No comments yet