VDB
CVE-2021-32653
CVE-2021-32653
PUBLISHED
CVSS 2.700000047683716 LOW
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, or 21.0.2 send user IDs to the lookup server even if the user has no fields set to published. The vulnerability is patched in versions 19.0.11, 20.0.10, and 21.0.2; no workarounds outside the updates are known to exist.
EPSS 0.38% · 59.8th percentile
Risk Scores
CVSS 3.1
2.700000047683716
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.38%
59.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nextcloud | nextcloud_server | 0, 20.0.0, 21.0.0 |
| nextcloud | security-advisories | < 19.0.11, >= 20.0.0, < 20.0.10, >= 21.0.0, < 21.0.2 |
Timeline
- CVE Published
- Jun 2, 2021 EPSS Score
- Jun 10, 2021 PoC Published
- Aug 4, 2021 EPSS Score
- Oct 4, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 3, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 5, 2022 EPSS Score
- Jun 5, 2022 EPSS Score
- Oct 6, 2022 EPSS Score