CVE-2021-32703 describes a lack of rate limiting on the shareinfo endpoint in Nextcloud Server versions prior to 19.0.13, 20.0.11, and 21.0.3, affecting both Nextcloud and Fedora distributions. This vulnerability, rated Medium with a CVSS score of 5.3, allows an unauthenticated attacker to enumerate potentially valid share tokens due to the absence of rate limiting. The attack complexity is low, and it primarily impacts confidentiality by potentially revealing sensitive share information. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 19.0.13CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* | ||
>= 20.0.0, < 20.0.11CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* | ||
>= 21.0.0, < 21.0.3CPE matchmatch criteria | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* | ||
33CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:* | ||
34CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.