Skip to main content

Incorrect Ownership Assignment

CVE-2021-32726

Severity High
Score 7.1/10

Summary

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

  • HIGH
  • NETWORK
  • HIGH
  • UNCHANGED
  • REQUIRED
  • LOW
  • HIGH
  • HIGH

CWE-708 - Incorrect Ownership Assignment

The software assigns an owner to a resource, but the owner is outside of the intended control sphere.

References

Advisory Timeline

  • Published