Bugzilla – Bug 1196908
VUL-0: CVE-2021-41241: nextcloud: groupfolders advanced permissions is not obeyed for subfolders
Last modified: 2022-04-08 11:34:46 UTC
CVE-2021-41241 Nextcloud server is a self hosted system designed to provide cloud style services. The groupfolders application for Nextcloud allows sharing a folder with a group of people. In addition, it allows setting "advanced permissions" on subfolders, for example, a user could be granted access to the groupfolder but not specific subfolders. Due to a lacking permission check in affected versions, a user could still access these subfolders by copying the groupfolder to another location. It is recommended that the Nextcloud Server is upgraded to 20.0.14, 21.0.6 or 22.2.1. Users unable to upgrade should disable the "groupfolders" application in the admin settings. Upstream fix: https://github.com/nextcloud/server/pull/29362/commits/9408f8ae6994666b685f5e2de588f9b2a79a00ed References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-41241 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-41241 https://github.com/nextcloud/security-advisories/security/advisories/GHSA-m4wp-r357-4q94 https://github.com/nextcloud/server/pull/29362 https://github.com/nextcloud/groupfolders/issues/1692
Only openSUSE:Backports:SLE-15-SP3 has an affected version.
This is an autogenerated message for OBS integration: This bug (1196908) was mentioned in https://build.opensuse.org/request/show/962687 Backports:SLE-12 / nextcloud https://build.opensuse.org/request/show/962688 Backports:SLE-15-SP3 / nextcloud https://build.opensuse.org/request/show/962689 Backports:SLE-15-SP4 / nextcloud
openSUSE-SU-2022:0089-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1196905,1196908,1196952 CVE References: CVE-2021-41239,CVE-2021-41241,CVE-2021-41741 JIRA References: Sources used: SUSE Package Hub for SUSE Linux Enterprise 12 (src): nextcloud-21.0.9-37.1
openSUSE-SU-2022:0098-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1196905,1196908,1196952 CVE References: CVE-2021-41239,CVE-2021-41241,CVE-2021-41741 JIRA References: Sources used: openSUSE Backports SLE-15-SP3 (src): nextcloud-21.0.9-bp153.2.12.1
Leap 15.3 have now 21.0.9