Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud Circles存在安全漏洞,该漏洞源于在受影响的版本中,Nextcloud Circles应用程序允许任何用户加入任何“秘密圈子”,而无需征得圈子所有者的同意,泄露私人信息。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 0.19.15 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-32802 | 9.3 CRITICAL | Preview generation used third-party library not suited for user-generated content in Nextc |
| CVE-2021-32800 | 8.1 HIGH | Bypass of Two Factor Authentication in Nextcloud server |
| CVE-2021-37628 | 7.5 HIGH | File Drop can be bypassed using Richdocuments app in nextcloud |
| CVE-2021-37631 | 6.5 MEDIUM | Circle can be accessed by non-Circle members in Nextcloud Deck |
| CVE-2021-32782 | 5.8 MEDIUM | Cross-Site Scripting in Nextcloud Circles |
| CVE-2021-32801 | 5.5 MEDIUM | Exceptions may have logged Encryption-at-Rest key content in Nextcloud server |
| CVE-2021-32766 | 5.3 MEDIUM | Nextcloud Text app can disclose existence of folders in "File Drop" link share |
| CVE-2021-37629 | 5.3 MEDIUM | Lack of ratelimit on Richdocuments OCS endpoint in nextcloud |
No comments yet