Skip to content

File Drop can be bypassed using Richdocuments app

High
LukasReschke published GHSA-pxhh-954f-8w7w Sep 6, 2021

Package

Richdocuments (Nextcloud)

Affected versions

< 3.8.4, < 4.2.1

Patched versions

3.8.4, 4.2.1

Description

Impact

The File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able to read arbitrary files in such a share.

Patches

It is recommended that the Nextcloud Richdocuments is upgraded to 3.8.4 or 4.2.1.

Workarounds

Disable the Richdocuments application.

References

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-37628

Weaknesses

Credits