CVE-2021-32680: Audit log is not properly logging unsetting of share expiration date

Published Jul 12, 2021
·
Updated

Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.

Affected Software

5 affected components
Nextcloud Server<19.0.13
Nextcloud Server>=20.0.0<20.0.11
Nextcloud Server>=21.0.0<21.0.3
fedoraproject fedora=33
fedoraproject fedora=34

Event History

Jul 12, 2021
CVE Published
via MITRE·01:25 PM
Data Sourced
via MITRE·01:25 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What is the severity of CVE-2021-32680?

CVE-2021-32680 has a medium severity rating due to improper logging of significant audit events.

2

How do I fix CVE-2021-32680?

To fix CVE-2021-32680, upgrade Nextcloud Server to versions 19.0.13, 20.0.11, or 21.0.3 or later.

3

Which versions of Nextcloud are affected by CVE-2021-32680?

CVE-2021-32680 affects Nextcloud Server versions prior to 19.0.13, 20.0.11, and 21.0.3.

4

What issues does CVE-2021-32680 cause for Nextcloud users?

CVE-2021-32680 causes audit logging failures that prevent proper tracking of share expiration date modifications.

5

Is CVE-2021-32680 specific to any particular operating system?

CVE-2021-32680 is not limited to any specific operating system but primarily affects Nextcloud Server installations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203