CVE-2021-32800
07.09.2021, 22:15
Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a password, or access to a WebAuthN trusted device of a user was sufficient to gain access to an account. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. There are no workaround for this vulnerability.Enginsight
| Vendor | Product | Version |
|---|---|---|
| nextcloud | nextcloud_server | 𝑥 < 20.0.12 |
| nextcloud | nextcloud_server | 21.0.0 ≤ 𝑥 < 21.0.4 |
| nextcloud | nextcloud_server | 22.0.0 ≤ 𝑥 < 22.1.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References