{"id":"CVE-2021-39223","details":"Nextcloud is an open-source, self-hosted productivity platform. The Nextcloud Richdocuments application prior to versions 3.8.6 and 4.2.3 returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. (e.g. an attacker could see that the file `shared.txt` is located within `/files/$username/Myfolder/Mysubfolder/shared.txt`). It is recommended that the Richdocuments application is upgraded to 3.8.6 or 4.2.3. As a workaround, disable the Richdocuments application in the app settings.","aliases":["GHSA-rjcc-4cgj-6v93"],"modified":"2026-07-09T10:01:25.212786Z","published":"2021-10-25T22:15:07.507Z","references":[{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-rjcc-4cgj-6v93"},{"type":"REPORT","url":"https://hackerone.com/reports/1253460"},{"type":"FIX","url":"https://github.com/nextcloud/richdocuments/pull/1760"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/richdocuments","events":[{"introduced":"0"},{"fixed":"ab63cbd1e3692ce7aae27cfca79d3073fc2b0de5"},{"introduced":"920fc643722b23fae8972ddc166c144e422ae575"},{"fixed":"b4b7db423701a49bc98e614c63ed6d85b5e5600d"}],"database_specific":{"cpe":"cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"3.8.6"},{"introduced":"4.0.0"},{"fixed":"4.2.3"}],"source":"CPE_RANGE"}}],"versions":["v3.8.5","v4.2.2","v4.2.1","v3.8.4","v3.8.3","v3.8.2","v4.1.2","v4.1.1","v3.8.1","v4.1.0","v3.8.0","untagged-4ba473c037918af19928","v3.7.19","v3.7.18","v3.7.17","v3.7.14","v4.0.4","v4.0.3","v3.7.16","v4.0.2","v4.0.1","v3.7.15","v4.0.0","v3.7.13","v3.7.12","v3.7.11","v3.7.10","v3.7.9","v3.7.8","v3.7.7","v3.7.6","v3.7.5","v3.7.4","v3.7.3","v3.7.2","v3.7.1","v3.7.0","v3.7.0-beta3","v3.7.0-beta2","v3.7.0-beta1","v3.6.0","v3.5.2","v3.5.1","v3.5.0","v3.4.6","v3.4.5","v3.4.4","v3.4.3","v3.4.2","v3.4.0-beta1","3.4.0-beta1","v3.4.1","v3.4.0","v3.3.15","v3.3.13","v3.3.12","v3.3.11","v3.3.10","v3.3.9","v3.3.8","v3.3.7","v3.3.6","v3.3.5","v3.3.4","v3.3.3","v3.3.2","v3.3.1","v3.3.0","v3.2.4","v3.2.3","v3.2.2","v3.2.1","v3.1.1","v3.1.0","v3.0.6","v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0-beta3","v3.0.0-beta2","v3.0.0-beta1","2.0.10","2.0.9","2.0.8","2.0.7","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","1.12.40","1.12.39","1.12.38","1.12.37","1.12.36","1.12.35","1.12.34","1.12.33","1.12.32","1.12.31","1.12.30","1.12.29","1.12.28","1.12.27","1.1.24","1.1.26","1.1.25","1.1.23","1.1.22"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-39223.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}