Lucene search

K
nextcloudNextcloudGHSA-7HVH-RC6F-PX23
HistoryOct 25, 2021 - 11:50 a.m.

Two-Factor Authentication not enforced for pages marked as public

2021-10-2511:50:00
github.com
28
two-factor authentication
public pages
nextcloud server upgrade
private chat channels

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

43.0%

Description

Impact

The Two-Factor Authentication wasn’t enforced for pages marked as public. Any page marked as @PublicPage could thus be accessed with a valid user session that isn’t authenticated.

This particularly affects the Nextcloud Talk application, as this could be leveraged to gain access to any private chat channel without going through the Two-Factor flow.

Patches

It is recommended that the Nextcloud Server is upgraded to 20.0.13, 21.0.5 or 22.2.0.

Workarounds

None.

References

For more information

If you have any questions or comments about this advisory:

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

43.0%