Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-37630


Nextcloud Circles is an open source social network built for the nextcloud ecosystem. In affected versions the Nextcloud Circles application allowed any user to join any "Secret Circle" without approval by the Circle owner leaking private information. It is recommended that Nextcloud Circles is upgraded to 0.19.15, 0.20.11 or 0.21.4. There are no workarounds for this issue.


Published

2021-09-07T20:15:07.847

Last Modified

2024-11-21T06:15:33.660

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Secondary
    CWE-639
  • Type: Primary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud circles < 0.19.5 Yes
Application nextcloud circles < 0.20.11 Yes
Application nextcloud circles < 0.21.4 Yes

References