CVE-2021-32656 log

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
A security issue has been found in Nextcloud Server before version 21.0.2. Nextcloud supports sharing of the registered users with other Nextcloud servers. Nextcloud supports adding these automated when selecting the "Add server automatically once a federated share was created successfully" setting.

As a public link can be added as federated share, an attacker can trigger this exchange if they have access to a public link, thus getting access to basic user information.
Group Package Affected Fixed Severity Status Ticket
AVG-2024 nextcloud 21.0.1-3 21.0.2-1 High Fixed
References
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-j875-vr2q-h6x6
https://hackerone.com/reports/1167853