CVE-2021-32680: Audit log is not properly logging unsetting of share expiration date
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32680?
CVE-2021-32680 has a medium severity rating due to improper logging of significant audit events.
How do I fix CVE-2021-32680?
To fix CVE-2021-32680, upgrade Nextcloud Server to versions 19.0.13, 20.0.11, or 21.0.3 or later.
Which versions of Nextcloud are affected by CVE-2021-32680?
CVE-2021-32680 affects Nextcloud Server versions prior to 19.0.13, 20.0.11, and 21.0.3.
What issues does CVE-2021-32680 cause for Nextcloud users?
CVE-2021-32680 causes audit logging failures that prevent proper tracking of share expiration date modifications.
Is CVE-2021-32680 specific to any particular operating system?
CVE-2021-32680 is not limited to any specific operating system but primarily affects Nextcloud Server installations.