CVE-2021-32705: Lack of ratelimit on public DAV endpoint
Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share tokens or credentials. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32705?
CVE-2021-32705 has a medium severity level due to the potential for credential enumeration.
How do I fix CVE-2021-32705?
To fix CVE-2021-32705, upgrade your Nextcloud Server to version 19.0.13, 20.0.11 or above, or 21.0.3 or above.
Which versions of Nextcloud Server are affected by CVE-2021-32705?
Versions prior to 19.0.13, 20.0.11, and 21.0.3 of Nextcloud Server are affected by CVE-2021-32705.
Can CVE-2021-32705 allow an attacker to exploit my Nextcloud server?
Yes, CVE-2021-32705 can allow an attacker to enumerate valid share tokens or credentials due to lack of ratelimiting.
Is there any mitigation for CVE-2021-32705 besides updating?
Currently, updating to the patched versions is the recommended and primary mitigation for CVE-2021-32705.