Bug 1188250 - (CVE-2021-32688) VUL-0: CVE-2021-32688: nextcloud: lacking permission check with application specific tokens
(CVE-2021-32688)
VUL-0: CVE-2021-32688: nextcloud: lacking permission check with application s...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Security
Leap 15.2
Other Other
: P3 - Medium : Minor (vote)
: ---
Assigned To: Eric Schirra
Security Team bot
https://smash.suse.de/issue/303836/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2021-07-13 10:43 UTC by Alexander Bergmann
Modified: 2021-11-07 12:14 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2021-07-13 10:43:05 UTC
CVE-2021-32688

Nextcloud Server is a Nextcloud package that handles data storage. Nextcloud
Server supports application specific tokens for authentication purposes. These
tokens are supposed to be granted to a specific applications (e.g. DAV sync
clients), and can also be configured by the user to not have any filesystem
access. Due to a lacking permission check, the tokens were able to change their
own permissions in versions prior to 19.0.13, 20.0.11, and 21.0.3. Thus
fileystem limited tokens were able to grant themselves access to the filesystem.
The issue is patched in versions 19.0.13, 20.0.11, and 21.0.3. There are no
known workarounds aside from upgrading.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-32688
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-32688
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-48m7-7r2r-838r
https://github.com/nextcloud/server/pull/27000
https://hackerone.com/reports/1193321
Comment 1 OBSbugzilla Bot 2021-07-13 13:10:30 UTC
This is an autogenerated message for OBS integration:
This bug (1188250) was mentioned in
https://build.opensuse.org/request/show/906122 15.2+Backports:SLE-12+Backports:SLE-15-SP1+Backports:SLE-15-SP2+Backports:SLE-15-SP3 / nextcloud
Comment 2 Swamp Workflow Management 2021-07-21 01:17:29 UTC
openSUSE-SU-2021:1068-1: An update that fixes 13 vulnerabilities is now available.

Category: security (important)
Bug References: 1181445,1181803,1181804,1188247,1188248,1188249,1188250,1188251,1188252,1188253,1188254,1188255,1188256
CVE References: CVE-2020-8293,CVE-2020-8294,CVE-2020-8295,CVE-2021-32678,CVE-2021-32679,CVE-2021-32680,CVE-2021-32688,CVE-2021-32703,CVE-2021-32705,CVE-2021-32725,CVE-2021-32726,CVE-2021-32734,CVE-2021-32741
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    nextcloud-20.0.11-lp152.3.9.1
openSUSE Backports SLE-15-SP3 (src):    nextcloud-20.0.11-bp153.2.3.1
openSUSE Backports SLE-15-SP2 (src):    nextcloud-20.0.11-bp152.2.9.1
openSUSE Backports SLE-15-SP1 (src):    nextcloud-20.0.11-bp151.3.15.1
Comment 3 Swamp Workflow Management 2021-07-21 01:19:55 UTC
openSUSE-SU-2021:1068-1: An update that fixes 13 vulnerabilities is now available.

Category: security (important)
Bug References: 1181445,1181803,1181804,1188247,1188248,1188249,1188250,1188251,1188252,1188253,1188254,1188255,1188256
CVE References: CVE-2020-8293,CVE-2020-8294,CVE-2020-8295,CVE-2021-32678,CVE-2021-32679,CVE-2021-32680,CVE-2021-32688,CVE-2021-32703,CVE-2021-32705,CVE-2021-32725,CVE-2021-32726,CVE-2021-32734,CVE-2021-32741
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    nextcloud-20.0.11-lp152.3.9.1
openSUSE Backports SLE-15-SP3 (src):    nextcloud-20.0.11-bp153.2.3.1
openSUSE Backports SLE-15-SP2 (src):    nextcloud-20.0.11-bp152.2.9.1
openSUSE Backports SLE-15-SP1 (src):    nextcloud-20.0.11-bp151.3.15.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    nextcloud-20.0.11-28.1
Comment 4 Eric Schirra 2021-11-07 12:14:25 UTC
Leap 15.2 has: version 2.0.12
Leap 15.3 has: version 2.0.12
Tumbleweed has: 22.2.0