CVE-2021-32680

LOW

Nextcloud Server <19.0.13, 20.0.11, 21.0.3 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.

References (6)

Core 6
Core References
Patch, Third Party Advisory x_refsource_misc
https://github.com/nextcloud/server/pull/27024
Permissions Required x_refsource_misc
https://hackerone.com/reports/1200810
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202208-17

Scores

CVSS v3 3.3
EPSS 0.0020
EPSS Percentile 41.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Details

CWE
CWE-778
Status published
Products (3)
fedoraproject/fedora 33
fedoraproject/fedora 34
nextcloud/nextcloud_server < 19.0.13
Published Jul 12, 2021
Tracked Since Feb 18, 2026