CVE-2021-22877
03.03.2021, 18:15
A missing user check in Nextcloud prior to 20.0.6 inadvertently populates a user's own credentials for other users external storage configuration when not already configured yet.Enginsight
| Vendor | Product | Version |
|---|---|---|
| nextcloud | nextcloud_server | 𝑥 < 20.0.6 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References