CVE-2021-37630: Secret Circle can be joined without approval in Nextcloud Circles
Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed any user to join any "Secret Circle" without approval by the Circle owner leaking private information. It is recommended that Nextcloud Circles is upgraded to 0.19.15, 0.20.11 or 0.21.4. There are no workarounds for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud Circlesto a version that resolves this vulnerability.Fixed in 0.19.15 - Upgrade
Upgrade
Nextcloud Circlesto a version that resolves this vulnerability.Fixed in 0.20.11 - Upgrade
Upgrade
Nextcloud Circlesto a version that resolves this vulnerability.Fixed in 0.21.4
Event History
Frequently Asked Questions
What is the severity of CVE-2021-37630?
CVE-2021-37630 has been classified as a medium severity vulnerability due to the exposure of private information.
How do I fix CVE-2021-37630?
To fix CVE-2021-37630, upgrade Nextcloud Circles to version 0.19.5 or later, or 0.20.11 or later, or 0.21.4 or later.
What are the affected versions of Nextcloud Circles for CVE-2021-37630?
The affected versions of Nextcloud Circles for CVE-2021-37630 include all versions prior to 0.19.5, any version from 0.20.0 to 0.20.11, and any version from 0.21.0 to 0.21.4.
What type of information is exposed due to CVE-2021-37630?
CVE-2021-37630 allows any user to join Secret Circles without approval, leading to potential leaking of private user information.
Who is impacted by CVE-2021-37630?
All users of the affected versions of the Nextcloud Circles application are potentially impacted by CVE-2021-37630.