LiveActive security incident?Get immediate response
CVE Record

CVE-2021-32703: Lack of ratelimit on shareinfo endpoint

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the shareinfo endpoint. This may have allowed an attacker to enumerate potentially valid share tokens. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

MediumCVSS 5.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This issue affected older Nextcloud Server releases by allowing repeated access to a share information endpoint without rate limiting. An unauthenticated network attacker may have been able to enumerate potentially valid share tokens. The vendor fixed it in later 19, 20, and 21 releases, and the sources state there are no known workarounds.

Executive priority

Schedule remediation in the normal vulnerability cycle, with faster handling for public Nextcloud systems. This is not evidenced as actively exploited in the bundle, but it affects unauthenticated network-facing behavior and could support abuse of shared-link workflows.

Technical view

CVE-2021-32703 is a CWE-799 rate-limiting flaw in Nextcloud Server's shareinfo endpoint before 19.0.13, 20.0.11, and 21.0.3. The CVSS 3.1 score is 5.3 with network attack vector, low complexity, no privileges, no user interaction, and low integrity impact. Public sources describe token enumeration risk, not direct data disclosure.

Likely exposure

Exposure is limited to Nextcloud Server deployments running versions before 19.0.13, 20.0.11, or 21.0.3 in the affected release lines. Internet-facing instances deserve priority because the CVSS vector indicates unauthenticated network reachability.

Exploitation context

The source bundle does not show CISA KEV listing or confirmed active exploitation. The vendor advisory says the flaw may have allowed enumeration of potentially valid share tokens. Treat this as plausible abuse against exposed systems, but not as confirmed in-the-wild exploitation from the provided evidence.

Researcher notes

Do not infer broader Nextcloud product impact beyond the listed Server versions. The available evidence identifies missing rate limiting on shareinfo and potential valid share-token enumeration. No vendor workaround is named, so remediation should be version or package update driven.

Mitigation direction

  • Upgrade Nextcloud Server to 19.0.13, 20.0.11, 21.0.3, or a later supported release.
  • Apply Fedora or Gentoo package updates if Nextcloud is installed through those distributions.
  • If upgrade is delayed, check current Nextcloud guidance; the provided sources cite no workaround.
  • Prioritize internet-facing and externally reachable Nextcloud instances for remediation.

Validation and detection

  • Inventory all Nextcloud Server deployments and record exact installed versions.
  • Confirm each affected release line is at or above the fixed version.
  • Check package manager advisories where Fedora or Gentoo packages are used.
  • Review whether affected Nextcloud instances are reachable from untrusted networks.
  • Review logs for unusual repeated access patterns against the shareinfo endpoint.
Prepared
Confidence
high
Sources
8

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-799: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-32703 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
7Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N3.91.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.3Medium
CVSS 3.1 vector shape for CVE-2021-32703Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
nextcloudsecurity-advisories< 19.0.13, >= 20.0.0, < 20.0.11, >= 21.0.0, < 21.0.3Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-799 · source CWE mapping

Improper Control of Interaction Frequency

Improper Control of Interaction Frequency represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.