CVE-2021-32705
Linux Fedora vulnerability analysis and mitigation

Overview

Nextcloud Server, a data storage package, was found to have a vulnerability in versions prior to 19.0.13, 20.011, and 21.0.3 due to a lack of ratelimiting on the public DAV endpoint. The vulnerability was discovered and disclosed in July 2021 (GitHub Advisory).

Technical details

The vulnerability stems from missing rate limiting controls on the public WebDAV endpoint, which could allow attackers to perform unlimited authentication attempts. This security flaw is tracked as CVE-2021-32705 with a CVSS v3.1 base score of 7.5 HIGH (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N). The issue is classified under CWE-307 (Improper Restriction of Excessive Authentication Attempts) and CWE-799 (Improper Control of Interaction Frequency) (NVD).

Impact

The vulnerability could allow an attacker to enumerate potentially valid share tokens or credentials through unlimited authentication attempts against the public DAV endpoint (GitHub Advisory).

Mitigation and workarounds

The vulnerability was patched in Nextcloud Server versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds, and users are strongly recommended to upgrade to the patched versions (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Fedora vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-13601HIGH7.7
  • Linux DebianLinux Debian
  • glib2-tests-debuginfo
NoYesNov 26, 2025
CVE-2025-13502HIGH7.5
  • Linux DebianLinux Debian
  • webkit2gtk3-jsc-devel
NoYesNov 25, 2025
CVE-2025-64761HIGH7.5
  • WolfiWolfi
  • openbao
NoYesNov 25, 2025
CVE-2025-65018HIGH7.1
  • NixOSNixOS
  • firefox-x11
NoYesNov 25, 2025
CVE-2025-64720HIGH7.1
  • NixOSNixOS
  • java-25-openjdk-src-fastdebug
NoYesNov 25, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management