CVE-2021-32676
Session Fixation in Nextcloud Talk
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nextcloud Talk is a fully on-premises audio/video and chat communication service. Password protected shared chats in Talk before version 9.0.10, 10.0.8 and 11.2.2 did not rotate the session cookie after a successful authentication event. It is recommended that the Nextcloud Talk App is upgraded to 9.0.10, 10.0.8 or 11.2.2. No workarounds for this vulnerability are known to exist.
Nextcloud Talk es un servicio de comunicación de audio/vídeo y chat totalmente local. Los chats compartidos protegidos por contraseña en Talk versiones anteriores a 9.0.10, 10.0.8 y 11.2.2 no rotaban la cookie de sesión después de un evento de autenticación con éxito. Es recomendado actualizar la aplicación Nextcloud Talk a las versiones 9.0.10, 10.0.8 o 11.2.2. No se conocen soluciones para esta vulnerabilidad
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-05-12 CVE Reserved
- 2021-06-16 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-384: Session Fixation
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-p6h7-84v4-827r | Third Party Advisory | |
https://hackerone.com/reports/1181962 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Talk Search vendor "Nextcloud" for product "Talk" | < 9.0.10 Search vendor "Nextcloud" for product "Talk" and version " < 9.0.10" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Talk Search vendor "Nextcloud" for product "Talk" | >= 10.0.0 < 10.0.8 Search vendor "Nextcloud" for product "Talk" and version " >= 10.0.0 < 10.0.8" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Talk Search vendor "Nextcloud" for product "Talk" | >= 11.2.0 < 11.2.2 Search vendor "Nextcloud" for product "Talk" and version " >= 11.2.0 < 11.2.2" | - |
Affected
|