Cyber Resilience

CVE-2021-32658

MediumPublic PoC

Published: 08 June 2021

Published
08 June 2021
Modified
21 November 2024
KEV Added
Patch
CVSS Score v3.1 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0014 34.4th percentile
Risk Priority 9 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2021-32658 is a medium-severity Exposure of Sensitive Information to an Unauthorized Actor (CWE-200) vulnerability in Nextcloud Nextcloud. Its CVSS base score is 4.7 (Medium).

Operationally, ranked at the 34.4th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog; a public proof-of-concept is referenced.

EU & UK References

Vulnerability details

Nextcloud Android is the Android client for the Nextcloud open source home cloud system. Due to a timeout issue the Android client may not properly clean all sensitive data on account removal. This could include sensitive key material such as…

more

the End-to-End encryption keys. It is recommended that the Nextcloud Android App is upgraded to 3.16.1

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

nextcloud
nextcloud
≤ 3.16.1

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-200 CWE-212

The control's identification, isolation, alerting, and eradication steps directly limit the impact and exploitation window of unauthorized sensitive information exposure.

addresses: CWE-200 CWE-212

Proper media downgrading process prevents sensitive information from remaining on media that is then accessible to lower-classification recipients.

addresses: CWE-200 CWE-212

Policies requiring periodic review and deletion of inaccurate/outdated PII reduce the amount of sensitive information retained and therefore exposed.

addresses: CWE-200 CWE-212

Regular deletion of inaccurate or outdated PII directly reduces the volume of sensitive information retained that could be exposed.

addresses: CWE-200 CWE-212

De-identification directly prevents exposure of sensitive/PII data to unauthorized actors when datasets are released or shared.

addresses: CWE-200 CWE-212

Deleting information when no longer needed directly reduces the window during which sensitive data can be exposed to unauthorized actors.

addresses: CWE-200 CWE-212

Secure disposal techniques directly prevent sensitive data from becoming accessible to unauthorized actors after components leave organizational control.

addresses: CWE-200

Automated marking applies security attributes to system outputs, making it harder for attackers to exploit unmarked sensitive information leading to unauthorized exposure.

References