Upstream information

CVE-2021-32680 at MITRE

Description

Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.

SUSE information

Overall state of this security issue: Resolved

This issue is currently not rated by SUSE as it is not affecting the SUSE Enterprise products.

CVSS v2 Scores
  National Vulnerability Database
Base Score 2.1
Vector AV:L/AC:L/Au:N/C:N/I:P/A:N
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None
CVSS v3 Scores
  National Vulnerability Database
Base Score 3.3
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector Local
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality Impact None
Integrity Impact Low
Availability Impact None
CVSSv3 Version 3.1
SUSE Bugzilla entry: 1188249 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Package Hub 12
  • nextcloud >= 20.0.11-28.1
  • nextcloud-apache >= 20.0.11-28.1
Patchnames:
openSUSE-2021-1068
SUSE Package Hub 15 SP1
  • nextcloud >= 20.0.11-bp151.3.15.1
  • nextcloud-apache >= 20.0.11-bp151.3.15.1
Patchnames:
openSUSE-2021-1068
SUSE Package Hub 15 SP2
  • nextcloud >= 20.0.11-bp152.2.9.1
  • nextcloud-apache >= 20.0.11-bp152.2.9.1
Patchnames:
openSUSE-2021-1068
SUSE Package Hub 15 SP3
  • nextcloud >= 20.0.11-bp153.2.3.1
  • nextcloud-apache >= 20.0.11-bp153.2.3.1
Patchnames:
openSUSE-2021-1068
openSUSE Leap 15.2
  • nextcloud >= 20.0.11-lp152.3.9.1
  • nextcloud-apache >= 20.0.11-lp152.3.9.1
Patchnames:
openSUSE-2021-1068
openSUSE Leap 15.3
  • nextcloud >= 20.0.11-bp153.2.3.1
  • nextcloud-apache >= 20.0.11-bp153.2.3.1
Patchnames:
openSUSE-2021-1068


SUSE Timeline for this CVE

CVE page created: Sun Nov 7 13:15:15 2021
CVE page last modified: Tue May 23 18:08:16 2023