Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud server 存在安全漏洞,该漏洞源于Nextcloud的groupfolders应用程序允许与一群人共享一个文件夹。Nextcloud server是一个自托管系统,旨在提供云风格的服务。此外,该漏洞允许攻击者对子文件夹设置“advanced permissions”,例如,用户可以被授予对groupfolders的访问权限,但不能被授予对特定子文件夹的访问权限。由于受影响的版本缺乏权限检
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 20.0.14 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2021-41239 | 5.3 MEDIUM | User enumeration setting not respected in Nextcloud server |
| CVE-2021-41180 | 4.7 MEDIUM | Geolocation preview links can be set to arbitrary links in nextcloud talk |
| CVE-2021-41181 | 2.4 LOW | Nextcloud Talk app exposes chat messages on lockscreen |
No comments yet