{"id":"CVE-2021-22906","details":"Nextcloud End-to-End Encryption before 1.5.3, 1.6.3 and 1.7.1 suffers from a denial of service vulnerability due to permitting any authenticated users to lock files of other users.","modified":"2026-04-10T04:30:18.973764Z","published":"2021-06-11T16:15:11.677Z","related":["GHSA-3829-45wm-ww36"],"references":[{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-3829-45wm-ww36"},{"type":"REPORT","url":"https://hackerone.com/reports/1189174"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/end_to_end_encryption","events":[{"introduced":"0"},{"fixed":"8ada9307c370f850c9b698b3d0331849d4657e0a"},{"introduced":"0"},{"fixed":"8dcaedc543ac454c95e4de85e5280d58ed7573a0"},{"introduced":"61ede2d8917813cae96b3fee9907d3dbd603c858"},{"fixed":"b8727c839f0d0e9cf22d2d7521f40709870922ba"}],"database_specific":{"versions":[{"introduced":"0"},{"fixed":"1.5.3"},{"introduced":"1.6.0"},{"fixed":"1.6.3"},{"introduced":"1.7.0"},{"fixed":"1.7.1"}]}}],"versions":["v1.0.0","v1.0.1","v1.0.4","v1.0.5","v1.5.0","v1.5.2","v1.5.2-beta1","v1.6.1","v1.6.2","v1.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-22906.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"}]}