CVE-2021-32726

Published
View on NVD ↗
CVSS v3
7.1
HIGH
CVSS v2
7.5
HIGH
Affected
2
PROJECTS

Description

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

👮 Security advisories of Nextcloud
GitHubGitHub
75
☁️ Nextcloud server, a safe home for all your data
GitHubGitHub
35.9K