CVE-2021-32726
12.07.2021, 20:15
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.Enginsight
| Vendor | Product | Version |
|---|---|---|
| nextcloud | nextcloud_server | 𝑥 < 19.0.13 |
| nextcloud | nextcloud_server | 20.0.0 ≤ 𝑥 < 20.0.11 |
| nextcloud | nextcloud_server | 21.0.0 ≤ 𝑥 < 21.0.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-708 - Incorrect Ownership AssignmentThe software assigns an owner to a resource, but the owner is outside of the intended control sphere.
- CWE-287 - Improper AuthenticationWhen an actor claims to have a given identity, the software does not prove or insufficiently proves that the claim is correct.
References