CVE-2021-32688Improper Authorization in Security-advisories

Severity
8.8HIGHNVD
EPSS
3.1%
top 13.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12

Description

Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server supports application specific tokens for authentication purposes. These tokens are supposed to be granted to a specific applications (e.g. DAV sync clients), and can also be configured by the user to not have any filesystem access. Due to a lacking permission check, the tokens were able to change their own permissions in versions prior to 19.0.13, 20.0.11, and 21.0.3. Thus fileystem limited tokens were able to gr

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages2 packages

NVDnextcloud/nextcloud_server20.0.020.0.11+2
CVEListV5nextcloud/security-advisories< 19.0.13+2

Also affects: Fedora 33, 34

Patches

🔴Vulnerability Details

1
CVEList
Application specific tokens can change their own scope2021-07-12
CVE-2021-32688 — Improper Authorization | cvebase