LiveActive security incident?Get immediate response
CVE Record

CVE-2021-32705: Lack of ratelimit on public DAV endpoint

Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, there was a lack of ratelimiting on the public DAV endpoint. This may have allowed an attacker to enumerate potentially valid share tokens or credentials. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.

MediumCVSS 5.3Not KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-32705 is a Nextcloud Server issue where a public DAV endpoint lacked rate limiting. An unauthenticated attacker could repeatedly guess values and potentially identify valid share tokens or credentials. The business risk is exposure of sharing access paths, not system takeover. Vendor sources state fixed versions are available and no workaround is known.

Executive priority

Treat as a medium-priority internet-facing service fix. It does not indicate active exploitation or full compromise, but the affected endpoint is public and may help attackers discover valid access material. Upgrade during the next security maintenance window, sooner for exposed production systems.

Technical view

Affected Nextcloud Server versions before 19.0.13, 20.0.11, and 21.0.3 did not rate-limit the public DAV endpoint. The CVSS 3.1 score is 5.3, network exploitable, low complexity, no privileges or user interaction required. The documented impact is potential enumeration of valid share tokens or credentials.

Likely exposure

Exposure is most likely on internet-accessible Nextcloud Server deployments running <19.0.13, 20.0.0-20.0.10, or 21.0.0-21.0.2. Systems using downstream Fedora or Gentoo packages should verify distro advisory package status.

Exploitation context

The source bundle does not show CISA KEV listing or cited evidence of active exploitation. The issue is plausible remotely because the endpoint is public and unauthenticated, but sources describe enumeration potential rather than confirmed compromise activity.

Researcher notes

The evidence supports a rate-limiting flaw on the public DAV endpoint with enumeration impact. Avoid expanding scope beyond Nextcloud Server versions named in the advisory. No public source in the bundle establishes active exploitation, exploit tooling, or a workaround.

Mitigation direction

  • Upgrade Nextcloud Server to 19.0.13, 20.0.11, 21.0.3, or later supported releases.
  • Apply relevant Fedora or Gentoo package updates where Nextcloud is distro-managed.
  • Do not rely on a workaround; the advisory states none are known.
  • Review vendor guidance before changing DAV exposure or share-link behavior.

Validation and detection

  • Inventory all Nextcloud Server instances and record exact versions.
  • Confirm each instance is at or above the fixed version for its release line.
  • Check package manager advisory status for Fedora or Gentoo deployments.
  • Review logs for unusual repeated requests against public DAV endpoints.
  • Confirm public share and credential management policies are documented.
Prepared
Confidence
high
Sources
8

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cwe · low confidence lookup

CWE-799: Exact CWE lookup

Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2021-32705 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Medium
CVSS
5.3 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
7Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
5.3CVSS 3.1MediumCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N3.91.4Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

5.3Medium
CVSS 3.1 vector shape for CVE-2021-32705Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
nextcloudsecurity-advisories< 19.0.13, >= 20.0.0, < 20.0.11, >= 21.0.0, < 21.0.3Listed
Weakness

CWE details

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.

CWE-799 · source CWE mapping

Improper Control of Interaction Frequency

Improper Control of Interaction Frequency represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.