Security readout for executives and security teams
Plain-English summary
This issue affected older Nextcloud Server releases by allowing repeated access to a share information endpoint without rate limiting. An unauthenticated network attacker may have been able to enumerate potentially valid share tokens. The vendor fixed it in later 19, 20, and 21 releases, and the sources state there are no known workarounds.
Executive priority
Schedule remediation in the normal vulnerability cycle, with faster handling for public Nextcloud systems. This is not evidenced as actively exploited in the bundle, but it affects unauthenticated network-facing behavior and could support abuse of shared-link workflows.
Technical view
CVE-2021-32703 is a CWE-799 rate-limiting flaw in Nextcloud Server's shareinfo endpoint before 19.0.13, 20.0.11, and 21.0.3. The CVSS 3.1 score is 5.3 with network attack vector, low complexity, no privileges, no user interaction, and low integrity impact. Public sources describe token enumeration risk, not direct data disclosure.
Likely exposure
Exposure is limited to Nextcloud Server deployments running versions before 19.0.13, 20.0.11, or 21.0.3 in the affected release lines. Internet-facing instances deserve priority because the CVSS vector indicates unauthenticated network reachability.
Exploitation context
The source bundle does not show CISA KEV listing or confirmed active exploitation. The vendor advisory says the flaw may have allowed enumeration of potentially valid share tokens. Treat this as plausible abuse against exposed systems, but not as confirmed in-the-wild exploitation from the provided evidence.
Researcher notes
Do not infer broader Nextcloud product impact beyond the listed Server versions. The available evidence identifies missing rate limiting on shareinfo and potential valid share-token enumeration. No vendor workaround is named, so remediation should be version or package update driven.
Mitigation direction
- Upgrade Nextcloud Server to 19.0.13, 20.0.11, 21.0.3, or a later supported release.
- Apply Fedora or Gentoo package updates if Nextcloud is installed through those distributions.
- If upgrade is delayed, check current Nextcloud guidance; the provided sources cite no workaround.
- Prioritize internet-facing and externally reachable Nextcloud instances for remediation.
Validation and detection
- Inventory all Nextcloud Server deployments and record exact installed versions.
- Confirm each affected release line is at or above the fixed version.
- Check package manager advisories where Fedora or Gentoo packages are used.
- Review whether affected Nextcloud instances are reachable from untrusted networks.
- Review logs for unusual repeated access patterns against the shareinfo endpoint.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-799: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2021-32703 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.3 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N3.91.4Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.3MediumVector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Source materials
- CVE List V5 sourceCVE List V5
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-375p-cxxq-gc9pCVE reference · x_refsource_CONFIRM
- https://github.com/nextcloud/server/pull/26945CVE reference · x_refsource_MISC
- https://hackerone.com/reports/1173684CVE reference · x_refsource_MISC
- FEDORA-2021-9b421b78afCVE reference · vendor-advisory, x_refsource_FEDORA
- FEDORA-2021-6f327296feCVE reference · vendor-advisory, x_refsource_FEDORA
- GLSA-202208-17CVE reference · vendor-advisory, x_refsource_GENTOO
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Improper Control of Interaction Frequency
Improper Control of Interaction Frequency represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
