High severity7.5NVD Advisory· Published Sep 7, 2021· Updated Jun 17, 2026
CVE-2021-37628
CVE-2021-37628
Description
Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able to read arbitrary files in such a share. It is recommended that the Nextcloud Richdocuments is upgraded to 3.8.4 or 4.2.1. If upgrading is not possible then it is recommended to disable the Richdocuments application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*range: <3.8.4
- (no CPE)range: up to 3.8.4 or 4.2.1
- nextcloud/security-advisoriesv5Range: < 3.8.4
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/richdocuments/pull/1664nvdPatchThird Party Advisory
- github.com/nextcloud/security-advisories/security/advisories/GHSA-pxhh-954f-8w7wnvdThird Party Advisory
- hackerone.com/reports/1253403nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.