CVE-2021-32653: Default settings leak federated cloud ID to lookup server of all users
Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud Server versions prior to 19.0.11, 20.0.10, or 21.0.2 send user IDs to the lookup server even if the user has no fields set to published. The vulnerability is patched in versions 19.0.11, 20.0.10, and 21.0.2; no workarounds outside the updates are known to exist.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32653?
CVE-2021-32653 is rated as a moderate severity vulnerability that exposes user IDs to possible unauthorized access.
What versions of Nextcloud Server are affected by CVE-2021-32653?
CVE-2021-32653 affects Nextcloud Server versions prior to 19.0.11, 20.0.10, and 21.0.2.
How do I fix CVE-2021-32653?
To fix CVE-2021-32653, upgrade your Nextcloud Server to versions 19.0.11, 20.0.10, or 21.0.2 or later.
What impact does CVE-2021-32653 have on Nextcloud users?
CVE-2021-32653 may allow leaked user IDs even if those users have not set any fields to be published.
Is there a public exploit for CVE-2021-32653?
As of now, there is no publicly known exploit specifically for CVE-2021-32653.