Логотип exploitDog
product: "nextcloud_server"
Консоль
Логотип exploitDog

exploitDog

product: "nextcloud_server"

Количество 409

Количество 409

nvd логотип

CVE-2022-29163

около 3 лет назад

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.6 and 23.0.3, a user can create a link that is not password protected even if the administrator requires links to be password protected. Versions 22.2.6 and 23.0.3 contain a patch for this issue. There are currently no known workarounds.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-29163

около 3 лет назад

Nextcloud Server is the file server software for Nextcloud, a self-hos ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2022-24889

около 3 лет назад

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server that they do not need, thus expanding their attack surface unnecessarily. This issue is fixed in versions 21.0.8 , 22.2.4, and 23.0.1.

CVSS3: 2.4
EPSS: Низкий
debian логотип

CVE-2022-24889

около 3 лет назад

Nextcloud Server is the file server software for Nextcloud, a self-hos ...

CVSS3: 2.4
EPSS: Низкий
nvd логотип

CVE-2022-24888

около 3 лет назад

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1, it is possible to create files and folders that have leading and trailing \n, \r, \t, and \v characters. The server rejects files and folders that have these characters in the middle of their names, so this might be an opportunity for injection. This issue is fixed in versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1. There are currently no known workarounds.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2022-24888

около 3 лет назад

Nextcloud Server is the file server software for Nextcloud, a self-hos ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2022-24741

больше 3 лет назад

Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud Server is upgraded to 21.0.8 , 22.2.4 or 23.0.1. Users unable to upgrade should disable preview generation with the `'enable_previews'` config flag.

CVSS3: 3.5
EPSS: Низкий
debian логотип

CVE-2022-24741

больше 3 лет назад

Nextcloud server is an open source, self hosted cloud style services p ...

CVSS3: 3.5
EPSS: Низкий
nvd логотип

CVE-2021-41241

больше 3 лет назад

Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted access to the groupfolder but not specific subfolders. Due to a lacking permission check in affected versions, a user could still access these subfolders by copying the groupfolder to another location. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. Users unable to upgrade should disable the "groupfolders" application in the admin settings.

CVSS3: 4.3
EPSS: Низкий
debian логотип

CVE-2021-41241

больше 3 лет назад

Nextcloud server is a self hosted system designed to provide cloud sty ...

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2021-41239

больше 3 лет назад

Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance, even when user listings where disabled. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. There are no known workarounds.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2021-41239

больше 3 лет назад

Nextcloud server is a self hosted system designed to provide cloud sty ...

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2021-41233

больше 3 лет назад

Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful exploitation an attacker requires knowledge of the sharing link. It is recommended that users upgrade their Nextcloud Server to 20.0.14, 21.0.6 or 22.2.1. Users unable to upgrade should disable the Nextcloud Text application in the application settings.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2021-41177

больше 3 лет назад

Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (as as `AnonRateThrottle` or `UserRateThrottle`) was thus not rate limited on instances not having a memory cache backend configured. In the case of a default installation, this would notably include the rate-limits on the two factor codes. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5, or 22.2.0. As a workaround, enable a memory cache backend in `config.php`.

CVSS3: 8.1
EPSS: Низкий
debian логотип

CVE-2021-41177

больше 3 лет назад

Nextcloud is an open-source, self-hosted productivity platform. Prior ...

CVSS3: 8.1
EPSS: Низкий
nvd логотип

CVE-2021-32802

почти 4 года назад

Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud server was invoking a third-party library that wasn't suited for untrusted user-supplied content. There are several security concerns with passing user-generated content to this library, such as Server-Side-Request-Forgery, file disclosure or potentially executing code on the system. The risk depends on your system configuration and the installed library version. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. These versions do not use this library anymore. As a workaround users may disable previews by setting `enable_previews` to `false` in `config.php`.

CVSS3: 9.3
EPSS: Низкий
debian логотип

CVE-2021-32802

почти 4 года назад

Nextcloud server is an open source, self hosted personal cloud. Nextcl ...

CVSS3: 9.3
EPSS: Низкий
nvd логотип

CVE-2021-32801

почти 4 года назад

Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionality. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. If upgrading is not an option users are advised to disable system logging to resolve this issue until such time that an upgrade can be performed Note that ff you do not use the Encryption-at-Rest functionality of Nextcloud you are not affected by this bug.

CVSS3: 5.5
EPSS: Низкий
debian логотип

CVE-2021-32801

почти 4 года назад

Nextcloud server is an open source, self hosted personal cloud. In aff ...

CVSS3: 5.5
EPSS: Низкий
nvd логотип

CVE-2021-32800

почти 4 года назад

Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a password, or access to a WebAuthN trusted device of a user was sufficient to gain access to an account. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. There are no workaround for this vulnerability.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-29163

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 22.2.6 and 23.0.3, a user can create a link that is not password protected even if the administrator requires links to be password protected. Versions 22.2.6 and 23.0.3 contain a patch for this issue. There are currently no known workarounds.

CVSS3: 3.5
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-29163

Nextcloud Server is the file server software for Nextcloud, a self-hos ...

CVSS3: 3.5
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-24889

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server that they do not need, thus expanding their attack surface unnecessarily. This issue is fixed in versions 21.0.8 , 22.2.4, and 23.0.1.

CVSS3: 2.4
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-24889

Nextcloud Server is the file server software for Nextcloud, a self-hos ...

CVSS3: 2.4
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-24888

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1, it is possible to create files and folders that have leading and trailing \n, \r, \t, and \v characters. The server rejects files and folders that have these characters in the middle of their names, so this might be an opportunity for injection. This issue is fixed in versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1. There are currently no known workarounds.

CVSS3: 4.3
0%
Низкий
около 3 лет назад
debian логотип
CVE-2022-24888

Nextcloud Server is the file server software for Nextcloud, a self-hos ...

CVSS3: 4.3
0%
Низкий
около 3 лет назад
nvd логотип
CVE-2022-24741

Nextcloud server is an open source, self hosted cloud style services platform. In affected versions an attacker can cause a denial of service by uploading specially crafted files which will cause the server to allocate too much memory / CPU. It is recommended that the Nextcloud Server is upgraded to 21.0.8 , 22.2.4 or 23.0.1. Users unable to upgrade should disable preview generation with the `'enable_previews'` config flag.

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2022-24741

Nextcloud server is an open source, self hosted cloud style services p ...

CVSS3: 3.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-41241

Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted access to the groupfolder but not specific subfolders. Due to a lacking permission check in affected versions, a user could still access these subfolders by copying the groupfolder to another location. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. Users unable to upgrade should disable the "groupfolders" application in the admin settings.

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-41241

Nextcloud server is a self hosted system designed to provide cloud sty ...

CVSS3: 4.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-41239

Nextcloud server is a self hosted system designed to provide cloud style services. In affected versions the User Status API did not consider the user enumeration settings by the administrator. This allowed a user to enumerate other users on the instance, even when user listings where disabled. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. There are no known workarounds.

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-41239

Nextcloud server is a self hosted system designed to provide cloud sty ...

CVSS3: 5.3
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-41233

Nextcloud text is a collaborative document editing using Markdown built for the nextcloud server. Due to an issue with the Nextcloud Text application, which is by default shipped with Nextcloud Server, an attacker is able to access the folder names of "File Drop". For successful exploitation an attacker requires knowledge of the sharing link. It is recommended that users upgrade their Nextcloud Server to 20.0.14, 21.0.6 or 22.2.1. Users unable to upgrade should disable the Nextcloud Text application in the application settings.

CVSS3: 6.5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-41177

Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, Nextcloud Server did not implement a database backend for rate-limiting purposes. Any component of Nextcloud using rate-limits (as as `AnonRateThrottle` or `UserRateThrottle`) was thus not rate limited on instances not having a memory cache backend configured. In the case of a default installation, this would notably include the rate-limits on the two factor codes. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5, or 22.2.0. As a workaround, enable a memory cache backend in `config.php`.

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
debian логотип
CVE-2021-41177

Nextcloud is an open-source, self-hosted productivity platform. Prior ...

CVSS3: 8.1
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2021-32802

Nextcloud server is an open source, self hosted personal cloud. Nextcloud supports rendering image previews for user provided file content. For some image types, the Nextcloud server was invoking a third-party library that wasn't suited for untrusted user-supplied content. There are several security concerns with passing user-generated content to this library, such as Server-Side-Request-Forgery, file disclosure or potentially executing code on the system. The risk depends on your system configuration and the installed library version. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. These versions do not use this library anymore. As a workaround users may disable previews by setting `enable_previews` to `false` in `config.php`.

CVSS3: 9.3
1%
Низкий
почти 4 года назад
debian логотип
CVE-2021-32802

Nextcloud server is an open source, self hosted personal cloud. Nextcl ...

CVSS3: 9.3
1%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-32801

Nextcloud server is an open source, self hosted personal cloud. In affected versions logging of exceptions may have resulted in logging potentially sensitive key material for the Nextcloud Encryption-at-Rest functionality. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. If upgrading is not an option users are advised to disable system logging to resolve this issue until such time that an upgrade can be performed Note that ff you do not use the Encryption-at-Rest functionality of Nextcloud you are not affected by this bug.

CVSS3: 5.5
0%
Низкий
почти 4 года назад
debian логотип
CVE-2021-32801

Nextcloud server is an open source, self hosted personal cloud. In aff ...

CVSS3: 5.5
0%
Низкий
почти 4 года назад
nvd логотип
CVE-2021-32800

Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a password, or access to a WebAuthN trusted device of a user was sufficient to gain access to an account. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. There are no workaround for this vulnerability.

CVSS3: 8.1
0%
Низкий
почти 4 года назад

Уязвимостей на страницу