CVE-2021-39224
Dashboard / Vulnerabilities / CVE-2021-39224
Summary:
Details: Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud OfficeOnline application prior to version 1.1.1 returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. (e.g. an attacker could see that the file `shared.txt` is located within `/files/$username/Myfolder/Mysubfolder/shared.txt`). It is recommended that the OfficeOnline application is upgraded to 1.1.1. As a workaround, one may disable the OfficeOnline application in the app settings.
References: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-56wm-r6jm-3v9h, https://github.com/nextcloud/officeonline/pull/204
Affected packages
Package
Name:
Purl:
Affected ranges
Affected versions
v1.1.0
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
