Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud server 存在信息泄露漏洞,该漏洞源于用户状态API没有考虑管理员的用户枚举设置。Nextcloud server是一个自托管系统,旨在提供云风格的服务。这允许用户枚举实例上的其他用户,即使用户清单被禁用。Nextcloud server建议升级到20.0.14、21.0.6或22.2.1。没有已知的解决方法。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 20.0.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-41180 | 4.7 MEDIUM | Geolocation preview links can be set to arbitrary links in nextcloud talk |
| CVE-2021-41241 | 4.3 MEDIUM | Advanced permissions is not respected for subfolders in Nextcloud server |
| CVE-2021-41181 | 2.4 LOW | Nextcloud Talk app exposes chat messages on lockscreen |
No comments yet