VDB
CVE-2021-41179
CVE-2021-41179
PUBLISHED
CVSS 6.5 MEDIUM
De multiples vulnérabilités ont été découvertes dans les produits Nextcloud. Elles permettent à un attaquant de provoquer un contournement de la politique de sécurité et une atteinte à la confidentialité des données.
EPSS 0.51% · 66.9th percentile
Risk Scores
CVSS 3.1
6.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.51%
66.9th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| nextcloud | security-advisories | < 22.2.0, < 20.0.13, >= 21.0.0, < 21.0.5 |
| nextcloud | server | 22.1.1, 21.0.1, 20.0.3 |
| Nextcloud | N/A |
Exploit Intelligence
Timeline
- Oct 25, 2021 CVE Published
- Oct 26, 2021 EPSS Score
- Dec 21, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- Apr 12, 2022 EPSS Score
- Jun 7, 2022 EPSS Score
- Aug 3, 2022 EPSS Score
- Sep 28, 2022 EPSS Score
- Nov 23, 2022 EPSS Score
- Jan 19, 2023 EPSS Score
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2x96-38qg-3m72 advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fj39-4qx4-m3f2 advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jp9c-vpr3-m5rf advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vxcm-g5v4-637f advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-7hvh-rc6f-px23 advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-g36v-67gv-h757 advisory
- https://github.com/nextcloud/server/pull/28725 url
- https://hackerone.com/reports/1322865 url