VYPR

security-advisories

by Nextcloud

Source repositories

CVEs (233)

  • CVE-2021-39225HigOct 25, 2021
    risk 0.00cvss 8.1epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9,…

  • CVE-2021-39224LowOct 25, 2021
    risk 0.00cvss 3.5epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version 1.1.1 returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. (e.g. an attacker could see that the file…

  • CVE-2021-39223MedOct 25, 2021
    risk 0.00cvss 4.8epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to versions 3.8.6 and 4.2.3 returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. (e.g. an attacker could see…

  • CVE-2021-39221MedOct 25, 2021
    risk 0.00cvss 6.4epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Contacts application prior to version 4.0.3 was vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. For exploitation, a user would need to right-click on a malicious file and open the file…

  • CVE-2021-39220LowOct 25, 2021
    risk 0.00cvss 3.5epss 0.01

    Nextcloud is an open-source, self-hosted productivity platform The Nextcloud Mail application prior to versions 1.10.4 and 1.11.0 does by default not render images in emails to not leak the read state or user IP. The privacy filter failed to filter images with a relative…

  • CVE-2021-32801MedSep 7, 2021
    risk 0.00cvss 5.5epss 0.00

    Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionality. It is recommended that the Nextcloud Server is upgraded…

  • CVE-2021-32800HigSep 7, 2021
    risk 0.00cvss 8.1epss 0.02

    Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a password, or access to a WebAuthN trusted device of a user was sufficient to gain access to an account.…

  • CVE-2021-37629MedSep 7, 2021
    risk 0.00cvss 5.3epss 0.01

    Nextcloud Richdocuments is an open source collaborative office suite. In affected versions there is a lack of rate limiting on the Richdocuments OCS endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. It is recommended that the Nextcloud…

  • CVE-2021-37628HigSep 7, 2021
    risk 0.00cvss 7.5epss 0.02

    Nextcloud Richdocuments is an open source collaborative office suite. In affected versions the File Drop features ("Upload Only" public link shares in Nextcloud) can be bypassed using the Nextcloud Richdocuments app. An attacker was able to read arbitrary files in such a share.…

  • CVE-2021-32766MedSep 7, 2021
    risk 0.00cvss 5.3epss 0.01

    Nextcloud Text is an open source plaintext editing application which ships with the nextcloud server. In affected versions the Nextcloud Text application returned different error messages depending on whether a folder existed in a public link share. This is problematic in case…

  • CVE-2021-37631MedSep 7, 2021
    risk 0.00cvss 6.5epss 0.01

    Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions the Deck application didn't properly check membership of users in a Circle. This allowed other users in the…

  • CVE-2021-37630MedSep 7, 2021
    risk 0.00cvss 6.5epss 0.01

    Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed any user to join any "Secret Circle" without approval by the Circle owner leaking private information. It is recommended that…

  • CVE-2021-32782MedSep 7, 2021
    risk 0.00cvss 5.8epss 0.01

    Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application is vulnerable to a stored Cross-Site Scripting (XSS) vulnerability. Due the strict Content-Security-Policy shipped with Nextcloud, this…

  • CVE-2021-37617HigAug 18, 2021
    risk 0.00cvss 7.3epss 0.00

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. The Nextcloud Desktop Client invokes its uninstaller script when being installed to make sure there are no remnants of previous installations. In versions 3.0.3 through 3.2.4, the…

  • CVE-2021-32728MedAug 18, 2021
    risk 0.00cvss 6.5epss 0.01

    The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with a computer. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.3.0, the Nextcloud Desktop client fails to…

  • CVE-2021-32748MedJul 27, 2021
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Richdocuments in an open source self hosted online office. Nextcloud uses the WOPI ("Web Application Open Platform Interface") protocol to communicate with the Collabora Editor, the communication between these two services was not protected by a credentials or IP…

  • CVE-2021-32741MedJul 12, 2021
    risk 0.00cvss 5.3epss 0.01

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public share link mount endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue…

  • CVE-2021-32734LowJul 12, 2021
    risk 0.00cvss 3.1epss 0.01

    Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to the user. This could result in a full path disclosure on…

  • CVE-2021-32733MedJul 12, 2021
    risk 0.00cvss 4.8epss 0.01

    Nextcloud Text is a collaborative document editing application that uses Markdown. A cross-site scripting vulnerability is present in versions prior to 19.0.13, 20.0.11, and 21.0.3. The Nextcloud Text application shipped with Nextcloud server used a `text/html` Content-Type when…

  • CVE-2021-32727MedJul 12, 2021
    risk 0.00cvss 5.7epss 0.01

    Nextcloud Android Client is the Android client for Nextcloud. Clients using the Nextcloud end-to-end encryption feature download the public and private key via an API endpoint. In versions prior to 3.16.1, the Nextcloud Android client skipped a step that involved the client…

Page 11 of 12