Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2021-102887
HistorySep 09, 2021 - 12:00 a.m.

Nextcloud Circles Licensing Issues Vulnerability Vulnerability

2021-09-0900:00:00
China National Vulnerability Database
www.cnvd.org.cn
7
nextcloud
circles
authorization
vulnerability
versions
consent
secret circle
attacker
private information
cnvd

EPSS

0.001

Percentile

41.4%

Nextcloud Circles, an open source social network built by Nextcloud Germany for the Nextcloud ecosystem, is vulnerable to an authorization issue in versions prior to 0.19.15, 0.20.11, and 0.21.4, which stems from a vulnerability in the Nextcloud Circles The application allows any user to join any “secret circle” without the consent of the circle owner, which could be exploited by an attacker to join the circle and obtain private information.

EPSS

0.001

Percentile

41.4%

Related for CNVD-2021-102887