VDB
CVE-2021-32725
CVE-2021-32725
PUBLISHED
CVSS 3.5 LOW
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.
EPSS 1.21% · 66.5th percentile
Risk Scores
CVSS 3.1
3.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
EPSS Score
1.21%
66.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nextcloud | nextcloud_server | 0, 20.0.0, 21.0.0 |
| nextcloud | security-advisories | < 19.0.13, >= 20.0.0, < 20.0.11, >= 21.0.0, < 21.0.3 |
Timeline
- Jul 12, 2021 CVE Published
- Jul 13, 2021 EPSS Score
- Sep 11, 2021 EPSS Score
- Nov 10, 2021 EPSS Score
- Jan 9, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 10, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Jul 7, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Nov 5, 2022 EPSS Score
- Jan 4, 2023 EPSS Score