CVE-2021-22906: Medium severity Nextcloud End-to-end encryption vulnerability
Published Jun 11, 2021
·Updated
Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated users to lock files of other users.
Affected Software
3 affected components
Nextcloud End-to-end encryption<1.5.3
Nextcloud End-to-end encryption>=1.6.0<1.6.3
Nextcloud End-to-end encryption>=1.7.0<1.7.1
Event History
Jun 11, 2021
CVE Published
via MITRE·03:49 PM
Data Sourced
via MITRE·03:49 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-22906?
The severity of CVE-2021-22906 is rated as medium with a CVSS score of 6.5.
2
How can I mitigate CVE-2021-22906 vulnerability?
To mitigate CVE-2021-22906 vulnerability, it is recommended to update Nextcloud End-to-End Encryption to version 1.5.3, 1.6.3, or 1.7.1.
3
What is the CWE associated with CVE-2021-22906?
CVE-2021-22906 is associated with CWE-639 and CWE-400 vulnerabilities.