VDB
CVE-2021-32725
CVE-2021-32725
PUBLISHED
CVSS 3.5 LOW
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.
EPSS 0.27% · 50.7th percentile
Risk Scores
CVSS 3.1
3.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
EPSS Score
0.27%
50.7th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nextcloud | nextcloud_server | 0, 20.0.0, 21.0.0 |
| nextcloud | security-advisories | < 19.0.13, >= 20.0.0, < 20.0.11, >= 21.0.0, < 21.0.3 |
Exploit Intelligence
Timeline
- Jul 12, 2021 CVE Published
- Jul 13, 2021 EPSS Score
- Sep 11, 2021 EPSS Score
- Nov 9, 2021 EPSS Score
- Jan 8, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 9, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 7, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 4, 2022 EPSS Score
- Jan 2, 2023 EPSS Score