CWE
304
Advisory Published
Updated

CVE-2021-41179: Two-Factor Authentication not enforced for pages marked as public

First published: Mon Oct 25 2021(Updated: )

Nextcloud is an open-source, self-hosted productivity platform. Prior to Nextcloud Server versions 20.0.13, 21.0.5, and 22.2.0, the Two-Factor Authentication wasn't enforced for pages marked as public. Any page marked as `@PublicPage` could thus be accessed with a valid user session that isn't authenticated. This particularly affects the Nextcloud Talk application, as this could be leveraged to gain access to any private chat channel without going through the Two-Factor flow. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5 or 22.2.0. There are no known workarounds aside from upgrading.

Credit: security-advisories@github.com security-advisories@github.com

Affected SoftwareAffected VersionHow to fix
Nextcloud Server>=20.0.3<20.0.13
Nextcloud Server>=21.0.1<21.0.5
Nextcloud Server>=22.1.1<22.2.0
>=20.0.3<20.0.13
>=21.0.1<21.0.5
>=22.1.1<22.2.0

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is Nextcloud?

    Nextcloud is an open-source, self-hosted productivity platform.

  • What versions of Nextcloud Server are affected by CVE-2021-41179?

    Nextcloud Server versions 20.0.3 to 20.0.13, 21.0.1 to 21.0.5, and 22.1.1 to 22.2.0 are affected.

  • What is the severity of CVE-2021-41179?

    The severity of CVE-2021-41179 is medium with a CVSS score of 6.5.

  • How can an attacker exploit CVE-2021-41179?

    An attacker can exploit CVE-2021-41179 by accessing pages marked as `@PublicPage` without proper authentication through Two-Factor Authentication.

  • Are there any mitigations available for CVE-2021-41179?

    Yes, upgrading to Nextcloud Server versions 20.0.13, 21.0.5, or 22.2.0 or later fixes the vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203