CVE-2021-41178
Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files.
Does this matter?
Lower severity and a low EPSS score (1.78%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud is an open-source, self-hosted productivity platform. Prior to versions 20.0.13, 21.0.5, and 22.2.0, a file traversal vulnerability makes an attacker able to download arbitrary SVG images from the host system, including user provided files. This could also be leveraged into a XSS/phishing attack, an attacker could upload a malicious SVG file that mimics the Nextcloud login form and send a specially crafted link to victims. The XSS risk here is mitigated due to the fact that Nextcloud employs a strict Content-Security-Policy disallowing execution of arbitrary JavaScript. It is recommended that the Nextcloud Server be upgraded to 20.0.13, 21.0.5 or 22.2.0. There are no known workarounds aside from upgrading.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.78% probability · 77th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-23, CWE-434, CWE-22
- Affected
- nextcloud/server
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jp9c-vpr3-m5rfThird Party Advisory
- https://github.com/nextcloud/server/pull/28726Patch, Third Party Advisory
- https://hackerone.com/reports/1302155Permissions Required
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jp9c-vpr3-m5rfThird Party Advisory
- https://github.com/nextcloud/server/pull/28726Patch, Third Party Advisory
- https://hackerone.com/reports/1302155Permissions Required
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.