Skip to content

Attacker can obtain write access to any federated share/public link

High
LukasReschke published GHSA-jf9h-v24c-22g5 Jun 1, 2021

Package

Nextcloud Server

Affected versions

< 19.0.11, < 20.0.10, < 21.0.2

Patched versions

19.0.11, 20.0.10, 21.0.2

Description

Impact

An attacker is able to receive write/read privileges on any Federated File Share. Since public links can be added as federated file share, this can also be exploited on any public link. (e.g. to add malicious data into a folder, or get read access to a "Files Drop" link).

Patches

It is recommended that the Nextcloud Server is upgraded to 19.0.11, 20.0.10 or 21.0.2.

Workarounds

Disable Federated File Sharing.

References

For more information

If you have any questions or comments about this advisory:

Severity

High

CVE ID

CVE-2021-32654

Weaknesses

Credits