CVE-2021-32656 - log back

CVE-2021-32656 edited at 01 Jun 2021 20:03:26
Severity
- Unknown
+ Medium
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
Description
+ A security issue has been found in Nextcloud Server before version 21.0.2. Nextcloud supports sharing of the registered users with other Nextcloud servers. Nextcloud supports adding these automated when selecting the "Add server automatically once a federated share was created successfully" setting.
+
+ As a public link can be added as federated share, an attacker can trigger this exchange if they have access to a public link, thus getting access to basic user information.
References
+ https://github.com/nextcloud/security-advisories/security/advisories/GHSA-j875-vr2q-h6x6
+ https://hackerone.com/reports/1167853
Notes
CVE-2021-32656 created at 01 Jun 2021 19:56:59