CVE-2021-32725 LOW

CVE-2021-32725: Default share permissions not respected for federated reshares

Vendor Nextcloud
Product security-advisories
Weakness CWE-277
Published July 12, 2021
Last update August 3, 2024

CVSS base score

3.5/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

Key dates

02Disclosure timeline

July 12, 2021 CVE published
August 3, 2024 Record updated