First published: Mon Jul 12 2021(Updated: )
Nextcloud Server is a Nextcloud package that handles data storage. In versions priot to 19.0.13, 20.0.11, and 21.0.3, Nextcloud Server audit logging functionality wasn't properly logging events for the unsetting of a share expiration date. This event is supposed to be logged. This issue is patched in versions 19.0.13, 20.0.11, and 21.0.3.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | <19.0.13 | |
Nextcloud Nextcloud Server | >=20.0.0<20.0.11 | |
Nextcloud Nextcloud Server | >=21.0.0<21.0.3 | |
Fedoraproject Fedora | =33 | |
Fedoraproject Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32680 has a medium severity rating due to improper logging of significant audit events.
To fix CVE-2021-32680, upgrade Nextcloud Server to versions 19.0.13, 20.0.11, or 21.0.3 or later.
CVE-2021-32680 affects Nextcloud Server versions prior to 19.0.13, 20.0.11, and 21.0.3.
CVE-2021-32680 causes audit logging failures that prevent proper tracking of share expiration date modifications.
CVE-2021-32680 is not limited to any specific operating system but primarily affects Nextcloud Server installations.