CVE-2021-32703 - log back

CVE-2021-32703 edited at 13 Jul 2021 10:27:06
Severity
- Unknown
+ Low
Remote
- Unknown
+ Remote
Type
- Unknown
+ Information disclosure
Description
+ In Nextcloud Server versions prior to 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens.
References
+ https://github.com/nextcloud/security-advisories/security/advisories/GHSA-375p-cxxq-gc9p
+ https://hackerone.com/reports/1173684
+ https://github.com/nextcloud/server/pull/26945
+ https://github.com/nextcloud/server/commit/6bc2d6d68e19212ed83a2f3ce51ddbfcefa248ae
Notes
CVE-2021-32703 created at 13 Jul 2021 10:25:17