CVE-2021-32680 Affecting nextcloud package, versions [,19.0.13)[20.0.0,20.0.11)[21.0.0,21.0.3)


Severity

Recommended
0.0
low
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-NEXTCLOUD-2371431
  • published26 Jan 2022
  • disclosed12 Jul 2021
  • creditUnknown

Introduced: 12 Jul 2021

CVE-2021-32680  (opens in a new tab)

How to fix?

Upgrade nextcloud to version 19.0.13, 20.0.11, 21.0.3 or higher.

Overview

Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.

CVSS Scores

version 3.1