CVE-2021-39225
Missing permission check on Deck API
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Nextcloud is an open-source, self-hosted productivity platform. A missing permission check in Nextcloud Deck before 1.2.9, 1.4.5 and 1.5.3 allows another authenticated users to access Deck cards of another user. It is recommended that the Nextcloud Deck App is upgraded to 1.2.9, 1.4.5 or 1.5.3. There are no known workarounds aside from upgrading.
Nextcloud es una plataforma de productividad de código abierto y auto-alojada. Una falta de comprobación de permisos en Nextcloud Deck versiones anteriores a 1.2.9, 1.4.5 y 1.5.3, permitía a otro usuario autenticado acceder a las tarjetas de Deck de otro usuario. Es recomendado actualizar la aplicación Nextcloud Deck a las versiones 1.2.9, 1.4.5 o 1.5.3. No se presentan soluciones conocidas aparte de la actualización
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-16 CVE Reserved
- 2021-10-25 CVE Published
- 2023-05-18 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-639: Authorization Bypass Through User-Controlled Key
- CWE-862: Missing Authorization
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-2x96-38qg-3m72 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/nextcloud/deck/pull/3316 | 2022-04-25 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Nextcloud Search vendor "Nextcloud" | Deck Search vendor "Nextcloud" for product "Deck" | < 1.2.9 Search vendor "Nextcloud" for product "Deck" and version " < 1.2.9" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Deck Search vendor "Nextcloud" for product "Deck" | >= 1.3.0 < 1.4.5 Search vendor "Nextcloud" for product "Deck" and version " >= 1.3.0 < 1.4.5" | - |
Affected
| ||||||
Nextcloud Search vendor "Nextcloud" | Deck Search vendor "Nextcloud" for product "Deck" | >= 1.5.0 < 1.5.3 Search vendor "Nextcloud" for product "Deck" and version " >= 1.5.0 < 1.5.3" | - |
Affected
|