Impact
An attacker is able to receive write/read privileges on any Federated File Share. Since public links can be added as federated file share, this can also be exploited on any public link. (e.g. to add malicious data into a folder, or get read access to a "Files Drop" link).
Patches
It is recommended that the Nextcloud Server is upgraded to 19.0.11, 20.0.10 or 21.0.2.
Workarounds
Disable Federated File Sharing.
References
For more information
If you have any questions or comments about this advisory:
Impact
An attacker is able to receive write/read privileges on any Federated File Share. Since public links can be added as federated file share, this can also be exploited on any public link. (e.g. to add malicious data into a folder, or get read access to a "Files Drop" link).
Patches
It is recommended that the Nextcloud Server is upgraded to 19.0.11, 20.0.10 or 21.0.2.
Workarounds
Disable Federated File Sharing.
References
For more information
If you have any questions or comments about this advisory: