CVE-2021-41239

MEDIUM

Nextcloud <20.0.13, <21.0.5, <22.2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance, even when user listings where disabled. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. There are no known workarounds.

References (4)

Core 4
Core References
Issue Tracking, Third Party Advisory x_refsource_confirm
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g722-cm3h-8wrx
Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://github.com/nextcloud/server/issues/27122
Patch, Third Party Advisory x_refsource_misc
https://github.com/nextcloud/server/pull/29260
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202208-17

Scores

CVSS v3 5.3
EPSS 0.0037
EPSS Percentile 59.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-862 CWE-200
Status published
Products (2)
nextcloud/nextcloud_server 22.2.0
nextcloud/nextcloud_server < 20.0.14
Published Mar 08, 2022
Tracked Since Feb 18, 2026