VDB

CVE-2021-32725

CVE-2021-32725 PUBLISHED CVSS 3.5 LOW

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being respected for federated reshares of files and folders. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

EPSS 0.27% · 50.7th percentile

Risk Scores

CVSS 3.1
3.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N
EPSS Score
0.27%
50.7th percentile

Affected Products

VendorProductVersions
nextcloudnextcloud_server0, 20.0.0, 21.0.0
nextcloudsecurity-advisories< 19.0.13, >= 20.0.0, < 20.0.11, >= 21.0.0, < 21.0.3

Timeline

  • Jul 12, 2021 CVE Published
  • Jul 13, 2021 EPSS Score
  • Sep 11, 2021 EPSS Score
  • Nov 9, 2021 EPSS Score
  • Jan 8, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Mar 9, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 7, 2022 EPSS Score
  • Sep 5, 2022 EPSS Score
  • Nov 4, 2022 EPSS Score
  • Jan 2, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›