Skip to content

Exceptions may have logged Encryption-at-Rest key content

Low
LukasReschke published GHSA-mcpf-v65v-359h Sep 6, 2021

Package

Nextcloud Server

Affected versions

< 20.0.12, < 21.0.4, < 22.1.0

Patched versions

20.0.12, 21.0.4, 22.1.0

Description

Impact

Logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionality.

Patches

It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0

Workarounds

Disable logging.

Note: If you do not use the Encryption-at-Rest functionality of Nextcloud you are not affected by this bug.

References

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2021-32801

Weaknesses