← Back

CVE-2021-32741

nvd nist
Published: Jul 12, 2021Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

Affected (3)

1 product
Nextcloud Server
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Nextcloud
Before 19.0.13
From 20.0.0 to 20.0.11
From 21.0.0 to 21.0.3

References (6)

Source: security-advisories@github.com
PatchThird Party Advisory
Source: security-advisories@github.com
Permissions Required
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Permissions Required

Timeline

No history available yet.