Bug 1188253 (CVE-2021-32725)

Summary: VUL-0: CVE-2021-32725: nextcloud: default share permissions were not being respected for federated reshares of files and folders
Product: [openSUSE] openSUSE Distribution Reporter: Alexander Bergmann <abergmann>
Component: SecurityAssignee: Eric Schirra <ecsos>
Status: RESOLVED FIXED QA Contact: Security Team bot <security-team>
Severity: Minor    
Priority: P3 - Medium    
Version: Leap 15.2   
Target Milestone: ---   
Hardware: Other   
OS: Other   
URL: https://smash.suse.de/issue/303781/
Whiteboard:
Found By: Security Response Team Services Priority:
Business Priority: Blocker: ---
Marketing QA Status: --- IT Deployment: ---

Description Alexander Bergmann 2021-07-13 10:43:15 UTC
CVE-2021-32725

Nextcloud Server is a Nextcloud package that handles data storage. In versions
prior to 19.0.13, 20.011, and 21.0.3, default share permissions were not being
respected for federated reshares of files and folders. The issue was fixed in
versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-32725
https://github.com/nextcloud/server/pull/26946
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32725
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6f6v-h9x9-jj4v
https://hackerone.com/reports/1178320
Comment 1 OBSbugzilla Bot 2021-07-13 13:10:42 UTC
This is an autogenerated message for OBS integration:
This bug (1188253) was mentioned in
https://build.opensuse.org/request/show/906122 15.2+Backports:SLE-12+Backports:SLE-15-SP1+Backports:SLE-15-SP2+Backports:SLE-15-SP3 / nextcloud
Comment 2 Swamp Workflow Management 2021-07-21 01:17:50 UTC
openSUSE-SU-2021:1068-1: An update that fixes 13 vulnerabilities is now available.

Category: security (important)
Bug References: 1181445,1181803,1181804,1188247,1188248,1188249,1188250,1188251,1188252,1188253,1188254,1188255,1188256
CVE References: CVE-2020-8293,CVE-2020-8294,CVE-2020-8295,CVE-2021-32678,CVE-2021-32679,CVE-2021-32680,CVE-2021-32688,CVE-2021-32703,CVE-2021-32705,CVE-2021-32725,CVE-2021-32726,CVE-2021-32734,CVE-2021-32741
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    nextcloud-20.0.11-lp152.3.9.1
openSUSE Backports SLE-15-SP3 (src):    nextcloud-20.0.11-bp153.2.3.1
openSUSE Backports SLE-15-SP2 (src):    nextcloud-20.0.11-bp152.2.9.1
openSUSE Backports SLE-15-SP1 (src):    nextcloud-20.0.11-bp151.3.15.1
Comment 3 Swamp Workflow Management 2021-07-21 01:20:16 UTC
openSUSE-SU-2021:1068-1: An update that fixes 13 vulnerabilities is now available.

Category: security (important)
Bug References: 1181445,1181803,1181804,1188247,1188248,1188249,1188250,1188251,1188252,1188253,1188254,1188255,1188256
CVE References: CVE-2020-8293,CVE-2020-8294,CVE-2020-8295,CVE-2021-32678,CVE-2021-32679,CVE-2021-32680,CVE-2021-32688,CVE-2021-32703,CVE-2021-32705,CVE-2021-32725,CVE-2021-32726,CVE-2021-32734,CVE-2021-32741
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    nextcloud-20.0.11-lp152.3.9.1
openSUSE Backports SLE-15-SP3 (src):    nextcloud-20.0.11-bp153.2.3.1
openSUSE Backports SLE-15-SP2 (src):    nextcloud-20.0.11-bp152.2.9.1
openSUSE Backports SLE-15-SP1 (src):    nextcloud-20.0.11-bp151.3.15.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    nextcloud-20.0.11-28.1
Comment 4 Marcus Meissner 2021-08-18 15:19:40 UTC
done