cbcvebase.
CVE-2021-32676
published 2021-06-16

CVE-2021-32676: Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and…

PriorityP336medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.95%
56.9th percentile
Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk App is upgraded to 9.0.10, 10.0.8 or 11.2.2. No workarounds for this vulnerability are known to exist.

Affected

6 ranges
VendorProductVersion rangeFixed in
nextcloudsecurity-advisories< 9.0.109.0.10
nextcloudsecurity-advisories
nextcloudsecurity-advisories
nextcloudtalk< 9.0.109.0.10
nextcloudtalk>= 10.0.0 < 10.0.810.0.8
nextcloudtalk>= 11.2.0 < 11.2.211.2.2

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.