Lack of Ratelimiting on Nextcloud Server's Public DAV Endpoint Allows Enumeration of Share Tokens and Credentials

Lack of Ratelimiting on Nextcloud Server's Public DAV Endpoint Allows Enumeration of Share Tokens and Credentials

CVE-2021-32705 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share tokens or credentials. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

Learn more about our Cis Benchmark Audit For Server Software.