CVE-2021-32725
- EPSS 0.27%
- Veröffentlicht 12.07.2021 20:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:36
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0....
CVE-2021-32703
- EPSS 0.56%
- Veröffentlicht 12.07.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:33
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share to...
CVE-2021-32705
- EPSS 0.57%
- Veröffentlicht 12.07.2021 16:15:09
- Zuletzt bearbeitet 21.11.2024 06:07:34
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share t...
CVE-2021-32680
- EPSS 0.2%
- Veröffentlicht 12.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:31
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event...
CVE-2021-32688
- EPSS 3.11%
- Veröffentlicht 12.07.2021 14:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:32
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can ...
CVE-2021-32679
- EPSS 0.81%
- Veröffentlicht 12.07.2021 13:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:30
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, filenames where not escaped by default in controllers using `DownloadResponse`. When a user-supplied filename was passed unsanitized...
CVE-2021-32678
- EPSS 0.3%
- Veröffentlicht 12.07.2021 13:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:30
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.0.11, and 21.0.3, ratelimits are not applied to OCS API responses. This affects any OCS API controller (`OCSController`) using the `@BruteForceProtect...
CVE-2021-22915
- EPSS 0.49%
- Veröffentlicht 11.06.2021 16:15:11
- Zuletzt bearbeitet 21.11.2024 05:50:54
Nextcloud server before 19.0.11, 20.0.10, 21.0.2 is vulnerable to brute force attacks due to lack of inclusion of IPv6 subnets in rate-limiting considerations. This could potentially result in an attacker bypassing rate-limit controls such as the Nex...
CVE-2021-32656
- EPSS 0.42%
- Veröffentlicht 01.06.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:28
Nextcloud Server is a Nextcloud package that handles data storage. A vulnerability in federated share exists in versions prior to 19.0.11, 20.0.10, and 21.0.2. An attacker can gain access to basic information about users of a server by accessing a pu...
CVE-2021-32657
- EPSS 0.49%
- Veröffentlicht 01.06.2021 22:15:08
- Zuletzt bearbeitet 21.11.2024 06:07:28
Nextcloud Server is a Nextcloud package that handles data storage. In versions of Nextcloud Server prior to 10.0.11, 20.0.10, and 21.0.2, a malicious user may be able to break the user administration page. This would disallow administrators to admini...