CVE-2021-32688
Summary
| CVE | CVE-2021-32688 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-12 14:15:00 UTC |
| Updated | 2023-11-07 03:35:00 UTC |
| Description | Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, the tokens were able to change their own permissions in versions prior to 19.0.13, 20.0.11, and 21.0.3. Thus fileystem limited tokens were able to grant themselves access to the filesystem. The issue is patched in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds aside from upgrading. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: nextcloud-20.0.11-1.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Harden apptoken check by rullzer · Pull Request #27000 · nextcloud/server · GitHub |
MISC |
github.com |
|
| Nextcloud: Multiple Vulnerabilities (GLSA 202208-17) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Application specific tokens can change their own scope · Advisory · nextcloud/security-advisories · GitHub |
CONFIRM |
github.com |
|
| [SECURITY] Fedora 33 Update: nextcloud-19.0.13-1.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| HackerOne |
MISC |
hackerone.com |
|
| [SECURITY] Fedora 33 Update: nextcloud-19.0.13-1.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 34 Update: nextcloud-20.0.11-1.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 281735 Fedora Security Update for nextcloud (FEDORA-2021-9b421b78af)
- 281736 Fedora Security Update for nextcloud (FEDORA-2021-6f327296fe)
- 710590 Gentoo Linux Nextcloud Multiple Vulnerabilities (GLSA 202208-17)
- 750849 OpenSUSE Security Update for nextcloud (openSUSE-SU-2021:1068-1)
- 750850 OpenSUSE Security Update for nextcloud (openSUSE-SU-2021:1068-1)