{"id":"openSUSE-SU-2021:1068-1","summary":"Security update for nextcloud","details":"This update for nextcloud fixes the following issues:\n\nnextcloud was updated to 20.0.11:\n\n- Fix boo#1188247 - CVE-2021-32678: OCS API response ratelimits are not applied\n- Fix boo#1188248 - CVE-2021-32679: filenames where not escaped by default in controllers using DownloadResponse\n- Fix boo#1188249 - CVE-2021-32680: share expiration date wasn't properly logged\n- Fix boo#1188250 - CVE-2021-32688: lacking permission check with application specific tokens\n- Fix boo#1188251 - CVE-2021-32703: lack of ratelimiting on the shareinfo endpoint\n- Fix boo#1188252 - CVE-2021-32705: lack of ratelimiting on the public DAV endpoint\n- Fix boo#1188253 - CVE-2021-32725: default share permissions were not being respected for federated reshares of files and folders\n- Fix boo#1188254 - CVE-2021-32726: webauthn tokens were not deleted after a user has been deleted\n- Fix boo#1188255 - CVE-2021-32734: possible full path disclosure on shared files\n- Fix boo#1188256 - CVE-2021-32741: lack of ratelimiting on the public share link mount endpoint\n- Bump handlebars from 4.7.6 to 4.7.7 (server#26900)\n- Bump lodash from 4.17.20 to 4.17.21 (server#26909)\n- Bump hosted-git-info from 2.8.8 to 2.8.9 (server#26920)\n- Don't break OCC if an app is breaking in it's Application class (server#26954)\n- Add bruteforce protection to the shareinfo endpoint (server#26956)\n- Ignore readonly flag for directories (server#26965)\n- Throttle MountPublicLinkController when share is not found (server#26971)\n- Respect default share permissions for federated reshares (server#27001)\n- Harden apptoken check (server#27014)\n- Use parent wrapper to properly handle moves on the same source/target storage (server#27016)\n- Fix error when using CORS with no auth credentials (server#27027)\n- Fix return value of getStorageInfo when 'quota_include_external_storage' is enabled (server#27108)\n- Bump patch dependencies (server#27183)\n- Use noreply@ as email address for share emails (server#27209)\n- Bump p-queue from 6.6.1 to 6.6.2 (server#27226)\n- Bump browserslist from 4.14.0 to 4.16.6 (server#27247)\n- Bump webpack from 4.44.1 to 4.44.2 (server#27297)\n- Properly use limit and offset for search in Jail wrapper (server#27308)\n- Make user:report command scale (server#27319)\n- Properly log expiration date removal in audit log (server#27325)\n- Propagate throttling on OCS response (server#27337)\n- Set umask before operations that create local files (server#27349)\n- Escape filename in Content-Disposition (server#27360)\n- Don't update statuses to offline again and again (server#27412)\n- Header must contain a colon (server#27456)\n- Activate constraint check for oracle / pqsql also for 20 (server#27523)\n- Only allow removing existing shares that would not be allowed due to reshare restrictions (server#27552)\n- Bump ws from 7.3.1 to 7.5.0 (server#27570)\n- Properly cleanup entries of WebAuthn on user deletion (server#27596)\n- Throttle on public DAV endpoint (server#27617)\n- Bump vue-loader from 15.9.3 to 15.9.7 (server#27639)\n- Bump eslint-plugin-standard from 4.0.1 to 4.0.2 (server#27651)\n- Validate the theming color also on CLI (server#27680)\n- Downstream encryption:fix-encrypted-version for repairing bad signature errors (server#27728)\n- Remove encodeURI code (files_pdfviewer#396)\n- Only ask for permissions on HTTPS (notifications#998)\n- Fix sorting if one of the file name is only composed with number (photos#785)\n- Backport 20 fix Photos not shown in large browser windows #630 (#686) (photos#810)\n- Update File.vue (photos#813)\n- Update chart.js (serverinfo#309)\n- Only return workspace property for top node in a propfind request (text#1611)\n- ViewerComponent: pass on autofocus to EditorWrapper (text#1647)\n- Use text/plain as content type for fetching the document (text#1692)\n- Log exceptions that happen on unknown exception and return generic messages (text#1698)\n- Add fixup (viewer#924)\n- Fix: fullscreen for Firefox (viewer#929)\n\nUpdate to 20.0.7\n\n- Catch NotFoundException when querying quota (server#25315)\n- CalDAV] Validate notified emails (server#25324)\n- Fix/app fetcher php compat comparison (server#25347)\n- Show the actual error on share requests (server#25352)\n- Fix parameter provided as string not array (server#25366)\n- The objectid is a string (server#25374)\n- 20.0.7 final (server#25387)\n- Properly handle SMB ACL blocking scanning a directory (server#25421)\n- Don't break completely when creating the digest fail for one user (activity#556)\n- Only attempt to use a secure view if hide download is actually set (files_pdfviewer#296)\n- Fix opening PDF files with special characters in their name (files_pdfviewer#298)\n- Fix PDF viewer failing on Edge (not based on Chromium) (files_pdfviewer#299)\n- Cannot unfold plain text notifications (notifications#846)\n- Remove EPUB mimetype (text#1391)\n\nUpdate to 20.0.6\n\n- Make sure to do priority app upgrades first (server#25077)\n- Respect DB restrictions on number of arguments in statements and queries (server#25120)\n- Add a hint about the direction of priority (server#25143)\n- Do not redirect to logout after login (server#25146)\n- Fix comparison of PHP versions (server#25152)\n- Add 'composer.lock' for acceptance tests to git (server#25178)\n- Update CRL due to revoked gravatar.crl (server#25190)\n- Don't log keys on checkSignature (server#25193)\n- Update 3rdparty after Archive_Tar (server#25199)\n- Bump CA bundle (server#25219)\n- Update handling of user credentials (server#25225)\n- Fix encoding issue with OC.Notification.show (server#25244)\n- Also use storage copy when dav copying directories (server#25261)\n- Silence log message (server#25263)\n- Extend ILDAPProvider to allow reading arbitrairy ldap attributes for users (server#25276)\n- Do not obtain userFolder of a federated user (server#25278)\n- Bump pear/archive_tar from 1.4.11 to 1.4.12 (3rdparty#603)\n- Add gitignore entry for .github folder of dependencies (3rdparty#604)\n- Clear event array on getting them (activity#551)\n\nUpdate to 20.0.5\n\n- Don't log params of imagecreatefromstring (server#24546)\n- Use storage copy implementation when doing dav copy\n  (server#24590)\n- Use in objectstore copy (server#24592)\n- Add tel, note, org and title search (server#24697)\n- Check php compatibility of app store app releases\n  (server#24698)\n- Fix #24682]: ensure federation cloud id is retruned if FN\n  property not found (server#24709)\n- Do not include non-required scripts on the upgrade page\n  (server#24714)\n- LDAP: fix inGroup for memberUid type of group memberships\n  (server#24716)\n- Cancel user search requests to avoid duplicate results being\n  added (server#24728)\n- Also unset the other possible unused paramters (server#24751)\n- Enables the file name check also to match name of mountpoints\n  (server#24760)\n- Fixes sharing to group ids with characters that are being url\n  encoded (server#24763)\n- Limit getIncomplete query to one row (server#24791)\n- Fix Argon2 descriptions (server#24792)\n- Actually set the TTL on redis set (server#24798)\n- Allow to force rename a conflicting calendar (server#24806)\n- Fix IPv6 localhost regex (server#24823)\n- Catch the error on heartbeat update (server#24826)\n- Make oc_files_trash.auto_id a bigint (server#24853)\n- Fix total upload size overwritten by next upload (server#24854)\n- Avoid huge exception argument logging (server#24876)\n- Make share results distinguishable if there are more than one\n  with the exact same display name (server#24878)\n- Add migration for oc_share_external columns (server#24963)\n- Don't throw a 500 when importing a broken ics reminder file\n  (server#24972)\n- Fix unreliable ViewTest (server#24976)\n- Update root.crl due to revocation of transmission.crt\n  (server#24990)\n- Set the JSCombiner cache if needed (server#24997)\n- Fix column name to check prior to deleting (server#25009)\n- Catch throwable instead of exception (server#25013)\n- Set the user language when adding the footer (server#25019)\n- Change defaultapp in config.sample.php to dashboard to improve\n  docs and align it to source code (server#25030)\n- Fix clearing the label of a share (server#25035)\n- Update psalm-baseline.xml (server#25066)\n- Don't remove assignable column for now (server#25074)\n- Add setup check to verify that the used DB version is still\n  supported… (server#25076)\n- Correctly set the user for activity parsing when preparing\n  a notifica… (activity#542)\n- Bump vue-virtual-grid from 2.2.1 to 2.3.0 (photos#597)\n- Catch possible database exceptions when fetching document data\n  (text#1221)\n- Make sure we have the proper PHP version installed before\n  running composer (text#1234)\n- Revert removal of transformResponse (text#1235)\n- Bump prosemirror-view from 1.16.1 to 1.16.5 (text#1255)\n- Bump @babel/preset-env from 7.12.1 to 7.12.11 (text#1257)\n- Bump babel-loader from 8.1.0 to 8.2.2 (text#1259)\n- Bump eslint-plugin-standard from 4.0.2 to 4.1.0 (text#1261)\n- Bump vue-loader from 15.9.5 to 15.9.6 (text#1263)\n- Bump prosemirror-model from 1.12.0 to 1.13.1 (text#1265)\n- Bump core-js from 3.7.0 to 3.8.1 (text#1266)\n- Bump stylelint from 13.7.2 to 13.8.0 (text#1269)\n- Bump @babel/plugin-transform-runtime from 7.12.1 to 7.12.10\n  (text#1271)\n- Bump sass-loader from 10.0.5 to 10.1.0 (text#1273)\n- Bump webpack-merge from 5.3.0 to 5.7.2 (text#1274)\n- Bump @babel/core from 7.12.3 to 7.12.10 (text#1277)\n- Bump cypress from 5.1.0 to 5.6.0 (text#1278)\n- Bump @vue/test-utils from 1.1.1 to 1.1.2 (text#1279)\n- Bump webpack-merge from 5.7.2 to 5.7.3 (text#1303)\n\n- The apache subpackage must require the main package, otherwise it\n  will not be uninstalled when the main package is uninstalled.\n\nUpdate to 20.0.4\n\n- Avoid dashboard crash when accessibility app is not installed (server#24636)\n- Bump ini from 1.3.5 to 1.3.7 (server#24649)\n- Handle owncloud migration to latest release (server#24653)\n- Use string for storing a OCM remote id (server#24654)\n- Fix MySQL database size calculation (serverinfo#262)\n- Bump cypress-io/github-action@v2 (viewer#722)\n- Fix] sidebar opening animation (viewer#723)\n- Fix not.exist cypress and TESTING checks (viewer#725)\n\n- Put apache configuration files in separate subpackage.\n\n- Use apache-rpm-macros for SUSE.\n- Change oc_* macros to nc_* macros.\n- Insert macro apache_serverroot also in cron files.\n\nUpdate to 20.0.3\n\n* Check quota of subdirectories when uploading to them (server#24181)\n* CircleId too short in some request (server#24196)\n* Missing level in ScopedPsrLogger (server#24212)\n* Fix nextcloud logo in email notifications misalignment (server#24228)\n* Allow selecting multiple columns with SELECT DISTINCT (server#24230)\n* Use file name instead of path in 'not allowed to share' message (server#24231)\n* Fix setting images through occ for theming (server#24232)\n* Use regex when searching on single file shares (server#24239)\n* Harden EncryptionLegacyCipher a bit (server#24249)\n* Update ScanLegacyFormat.php (server#24258)\n* Simple typo in comments (server#24259)\n* Use correct year for generated birthdays events (server#24263)\n* Delete files that exceed trashbin size immediately (server#24297)\n* Update sabre/xml to fix XML parsing errors (server#24311)\n* Only check path for being accessible when the storage is a object home (server#24325)\n* Avoid empty null default with value that will be inserted anyways (server#24333)\n* Fix contacts menu position and show uid as a tooltip (server#24342)\n* Fix the config key on the sharing expire checkbox (server#24346)\n* Set the display name of federated sharees from addressbook (server#24353)\n* Catch storage not available in versions expire command (server#24367)\n* Use proper bundles for files client and fileinfo (server#24377)\n* Properly encode path when fetching inherited shares (server#24387)\n* Formatting remote sharer should take protocol, path into account (server#24391)\n* Make sure we add new line between vcf groups exports (server#24443)\n* Fix public calendars shared to circles (server#24446)\n* Store scss variables under a different prefix for each theming config version (server#24453)\n* External storages: save group ids not display names in configuration (server#24455)\n* Use correct l10n source in files_sharing JS code (server#24462)\n* Set frame-ancestors to none if none are filled (server#24477)\n* Move the password fiels of chaging passwords to post (server#24478)\n* Move the global password for files external to post (server#24479)\n* Only attempt to move to trash if a file is not in appdata (server#24483)\n* Fix loading mtime of new file in conflict dialog in firefox (server#24491)\n* Harden setup check for TLS version if host is not reachable (server#24502)\n* Fix file size computation on 32bit platforms (server#24509)\n* Allow subscription to indicate that a userlimit is reached (server#24511)\n* Set mountid for personal external storage mounts (server#24513)\n* Only execute plain mimetype check for directories and do the fallback… (server#24517)\n* Fix vsprint parameter (server#24527)\n* Replace abandoned log normalizer with our fork (server#24530)\n* Add icon to user limit notification (server#24531)\n* Also run repair steps when encryption is disabled but a legacy key is present (server#24532)\n* [3rdparty][security] Archive TAR to 1.4.11 (server#24534)\n* Generate a new session id if the decrypting the session data fails (server#24553)\n* Revert 'Do not read certificate bundle from data dir by default' (server#24556)\n* Dont use system composer for autoload checker (server#24557)\n* Remember me is not an app_password (server#24563)\n* Do not load nonexisting setup.js (server#24582)\n* Update sabre/xml to fix XML parsing errors (3rdparty#529)\n* Use composer v1 on CI (3rdparty#532)\n* Bump pear/archive_tar from 1.4.9 to 1.4.11 (3rdparty#536)\n* Replace abandoned log normalizer with our fork (3rdparty#543)\n* Allow nullable values as subject params (activity#535)\n* Don't log when unknown array is null (notifications#803)\n* Feat/virtual grid (photos#550)\n* Make sure we have a string to localecompare to (photos#583)\n* Always get recommendations for dashboard if enabled (recommendations#336)\n* Properly fetch oracle database information (serverinfo#258)\n* Also register to urlChanged event to update RichWorkspace (text#1181)\n* Move away from GET (text#1214)\n\nUpdate to 20.0.2\n   \n* CVE-2020-8293: Fixed input validation which allowed users to store unlimited \n  data in workflow rules (boo#1181445). \n* CVE-2020-8294: Fixed a missing link validation (boo#1181803).\n* Inidicate preview availability in share api responses (server#23419)\n* CalDavBackend: check if timerange is array before accessing (server#23563)\n* Some emojis are in CHAR_CATEGORY_GENERAL_OTHER_TYPES (server#23575)\n* Also expire share type email (server#23583)\n* Only use index of mount point when it is there (server#23611)\n* Only retry fetching app store data once every 5 minutes in case it fails (server#23633)\n* Bring back the restore share button (server#23636)\n* Fix updates of NULL appconfig values (server#23641)\n* Fix sharing input placeholder for emails (server#23646)\n* Use bigint for fileid in filecache_extended (server#23690)\n* Enable theming background transparency (server#23699)\n* Fix sharer flag on ldap:show-remnants when user owned more than a single share (server#23702)\n* Make sure the function signatures of the backgroundjob match (server#23710)\n* Check if array elements exist before using them (server#23713)\n* Fix default quota display value in user row (server#23726)\n* Use lib instead if core as l10n module in OC_Files (server#23727)\n* Specify accept argument to avatar upload input field (server#23732)\n* Save email as lower case (server#23733)\n* Reset avatar cropper before showing (server#23736)\n* Also run the SabreAuthInitEvent for the main server (server#23745)\n* Type the \\OCP\\IUserManager::callForAllUsers closure with Psalm (server#23749)\n* Type the \\OCP\\AppFramework\\Services\\IInitialState::provideLazyInitial… (server#23751)\n* Don't overwrite the event if we use it later (server#23753)\n* Inform the user when flow config data exceeds thresholds (server#23759)\n* Type the \\OCP\\IUserManager::callForSeenUsers closure with Psalm (server#23763)\n* Catch errors when closing file conflict dialog (server#23774)\n* Document the backend registered events of LDAP (server#23779)\n* Fetch the logger and system config once for all query builder instances (server#23787)\n* Type the event dispatcher listener callables with Psalm (server#23789)\n* Only run phpunit when 'php' changed (server#23794)\n* Remove bold font-weight and lower font-size for empty search box (server#23829)\n* No need to check if there is an avatar available, because it is gener… (server#23846)\n* Ensure filepicker list is empty before populating (server#23850)\n* UserStatus: clear status message if message is null (server#23858)\n* Fix grid view toggle in tags view (server#23874)\n* Restrict query when searching for versions of trashbin files (server#23884)\n* Fix potentially passing null to events where IUser is expected (server#23894)\n* Make user status styles scoped (server#23899)\n* Move help to separate stylesheet (server#23900)\n* Add default font size (server#23902)\n* Do not emit UserCreatedEvent twice (server#23917)\n* Bearer must be in the start of the auth header (server#23924)\n* Fix casting of integer and boolean on Oracle (server#23935)\n* Skip already loaded apps in loadApps (server#23948)\n* Fix repair mimetype step to not leave stray cursors (server#23950)\n* Improve query type detection (server#23951)\n* Fix iLike() falsely turning escaped % and _ into wildcards (server#23954)\n* Replace some usages of OC_DB in OC\\Share\\* with query builder (server#23955)\n* Use query builder instead of OC_DB in trashbin (server#23971)\n* Fix greatest/least order for oracle (server#23975)\n* Fix link share label placeholder not showing (server#23992)\n* Unlock when promoting to exclusive lock fails (server#23995)\n* Make sure root storage is valid before checking its size (server#23996)\n* Use query builder instead of OC_DB in OC\\Files\\* (server#23998)\n* Shortcut to avoid file system setup when generating the logo URL (server#24001)\n* Remove old legacy scripts references (server#24004)\n* Fix js search in undefined ocs response (server#24012)\n* Don't leave cursors open (server#24033)\n* Fix sharing tab state not matching resharing admin settings (server#24044)\n* Run unit tests against oracle (server#24049)\n* Use png icons in caldav reminder emails (server#24050)\n* Manually iterate over calendardata when oracle is used (server#24058)\n* Make is_user_defined nullable so we can store false on oracle (server#24079)\n* Fix default internal expiration date enforce (server#24081)\n* Register new command db:add-missing-primary-keys (server#24106)\n* Convert the card resource to a string if necessary (server#24114)\n* Don't throw on SHOW VERSION query (server#24147)\n* Bump dompurify to 2.2.2 (server#24153)\n* Set up FS before querying storage info in settings (server#24156)\n* Fix default internal expiration date (server#24159)\n* CircleId too short in some request (server#24178)\n* Revert 'circleId too short in some request' (server#24183)\n* Missing level in ScopedPsrLogger (server#24212)\n* Fix activity spinner on empty activity (activity#523)\n* Add OCI github action (activity#528)\n* Disable download button by default (files_pdfviewer#257)\n* Feat/dependabot ga/stable20 (firstrunwizard#442)\n* Fix loading notifications without a message on oracle (notifications#796)\n* Do not setup appdata in constructor to avoid errors causing the whole instance to stop working (text#1105)\n* Bump eslint-plugin-standard from 4.0.1 to 4.0.2 (text#1125)\n* Bump sass-loader from 10.0.1 to 10.0.5 (text#1134)\n* Bump webpack from 4.44.1 to 4.44.2 (text#1140)\n* Bump dependencies to version in range (text#1164)\n* Validate link on click (text#1166)\n* Add migration to fix oracle issues with the database schema (text#1177)\n* Bump cypress from 4.12.1 to 5.1.0 (text#1179)\n* Fix URL escaping of shared files (viewer#681)\n* Fix component click outside and cleanup structure (viewer#684)\n\nUpdate to 20.0.1\n\nNo changelog from upstream at this time.\n\nUpdate to 20.0.0\n\n* Changes\n  The three biggest features we introduce with Nextcloud 20 are:\n  - Our new dashboard provides a great starting point for the day\n    with over a dozen widgets ranging from Twitter and Github to \n    Moodle and Zammad already available\n  - Search was unified, bringing search results of Nextcloud apps\n    as well as external services like Gitlab, Jira and Discourse\n    in one place\n  - Talk introduced bridging to other platforms including MS Teams,\n    Slack, IRC, Matrix and a dozen others\n  * Some other improvements we want to highlight include:\n    - Notifications and Activities were brought together, making \n      sure you won’t miss anything important\n    - We added a ‘status’ setting so you can communicate to other\n      users what you are up to\n    - Talk also brings dashboard and search integration, emoji picker,\n      upload view, camera and microphone settings, mute and more\n    - Calendar integrates in dashboard and search, introduced a list \n      view and design improvements\n    - Mail introduces threaded view, mailbox management and more\n    - Deck integrates with dashboard and search, introduces Calendar\n      integration, modal view for card editing and series of smaller \n      improvements\n    - Flow adds push notification and webhooks so other web apps\n      can easily integrate with Nextcloud\n    - Text introduced direct linking to files in Nextcloud\n    - Files lets you add a description to public link shares\n+ Read the full announcement on our blog\n- NC-SA-2020-037\n- CVE-2020-8295: Fixed Denial of service attack when resetting the password for a user(boo#1181804)\n- Update to 20.0.11\n- Fix boo#1188247 - CVE-2021-32678: OCS API response ratelimits are not applied\n- Fix boo#1188248 - CVE-2021-32679: filenames where not escaped by default in controllers using DownloadResponse\n- Fix boo#1188249 - CVE-2021-32680: share expiration date wasn't properly logged\n- Fix boo#1188250 - CVE-2021-32688: lacking permission check with application specific tokens\n- Fix boo#1188251 - CVE-2021-32703: lack of ratelimiting on the shareinfo endpoint\n- Fix boo#1188252 - CVE-2021-32705: lack of ratelimiting on the public DAV endpoint\n- Fix boo#1188253 - CVE-2021-32725: default share permissions were not being respected for federated reshares of files and folders\n- Fix boo#1188254 - CVE-2021-32726: webauthn tokens were not deleted after a user has been deleted\n- Fix boo#1188255 - CVE-2021-32734: possible full path disclosure on shared files\n- Fix boo#1188256 - CVE-2021-32741: lack of ratelimiting on the public share link mount endpoint\n- Bump handlebars from 4.7.6 to 4.7.7 (server#26900)\n- Bump lodash from 4.17.20 to 4.17.21 (server#26909)\n- Bump hosted-git-info from 2.8.8 to 2.8.9 (server#26920)\n- Don't break OCC if an app is breaking in it's Application class (server#26954)\n- Add bruteforce protection to the shareinfo endpoint (server#26956)\n- Ignore readonly flag for directories (server#26965)\n- Throttle MountPublicLinkController when share is not found (server#26971)\n- Respect default share permissions for federated reshares (server#27001)\n- Harden apptoken check (server#27014)\n- Use parent wrapper to properly handle moves on the same source/target storage (server#27016)\n- Fix error when using CORS with no auth credentials (server#27027)\n- Fix return value of getStorageInfo when 'quota_include_external_storage' is enabled (server#27108)\n- Bump patch dependencies (server#27183)\n- Use noreply@ as email address for share emails (server#27209)\n- Bump p-queue from 6.6.1 to 6.6.2 (server#27226)\n- Bump browserslist from 4.14.0 to 4.16.6 (server#27247)\n- Bump webpack from 4.44.1 to 4.44.2 (server#27297)\n- Properly use limit and offset for search in Jail wrapper (server#27308)\n- Make user:report command scale (server#27319)\n- Properly log expiration date removal in audit log (server#27325)\n- Propagate throttling on OCS response (server#27337)\n- Set umask before operations that create local files (server#27349)\n- Escape filename in Content-Disposition (server#27360)\n- Don't update statuses to offline again and again (server#27412)\n- Header must contain a colon (server#27456)\n- Activate constraint check for oracle / pqsql also for 20 (server#27523)\n- Only allow removing existing shares that would not be allowed due to reshare restrictions (server#27552)\n- Bump ws from 7.3.1 to 7.5.0 (server#27570)\n- Properly cleanup entries of WebAuthn on user deletion (server#27596)\n- Throttle on public DAV endpoint (server#27617)\n- Bump vue-loader from 15.9.3 to 15.9.7 (server#27639)\n- Bump eslint-plugin-standard from 4.0.1 to 4.0.2 (server#27651)\n- Validate the theming color also on CLI (server#27680)\n- Downstream encryption:fix-encrypted-version for repairing bad signature errors (server#27728)\n- Remove encodeURI code (files_pdfviewer#396)\n- Only ask for permissions on HTTPS (notifications#998)\n- Fix sorting if one of the file name is only composed with number (photos#785)\n- Backport 20 fix Photos not shown in large browser windows #630 (#686) (photos#810)\n- Update File.vue (photos#813)\n- Update chart.js (serverinfo#309)\n- Only return workspace property for top node in a propfind request (text#1611)\n- ViewerComponent: pass on autofocus to EditorWrapper (text#1647)\n- Use text/plain as content type for fetching the document (text#1692)\n- Log exceptions that happen on unknown exception and return generic messages (text#1698)\n- Add fixup (viewer#924)\n- Fix: fullscreen for Firefox (viewer#929)\n\nUpdate to 20.0.7\n\n- Catch NotFoundException when querying quota (server#25315)\n- CalDAV] Validate notified emails (server#25324)\n- Fix/app fetcher php compat comparison (server#25347)\n- Show the actual error on share requests (server#25352)\n- Fix parameter provided as string not array (server#25366)\n- The objectid is a string (server#25374)\n- 20.0.7 final (server#25387)\n- Properly handle SMB ACL blocking scanning a directory (server#25421)\n- Don't break completely when creating the digest fail for one user (activity#556)\n- Only attempt to use a secure view if hide download is actually set (files_pdfviewer#296)\n- Fix opening PDF files with special characters in their name (files_pdfviewer#298)\n- Fix PDF viewer failing on Edge (not based on Chromium) (files_pdfviewer#299)\n- Cannot unfold plain text notifications (notifications#846)\n- Remove EPUB mimetype (text#1391)\n\nUpdate to 20.0.6\n\n- Make sure to do priority app upgrades first (server#25077)\n- Respect DB restrictions on number of arguments in statements and queries (server#25120)\n- Add a hint about the direction of priority (server#25143)\n- Do not redirect to logout after login (server#25146)\n- Fix comparison of PHP versions (server#25152)\n- Add 'composer.lock' for acceptance tests to git (server#25178)\n- Update CRL due to revoked gravatar.crl (server#25190)\n- Don't log keys on checkSignature (server#25193)\n- Update 3rdparty after Archive_Tar (server#25199)\n- Bump CA bundle (server#25219)\n- Update handling of user credentials (server#25225)\n- Fix encoding issue with OC.Notification.show (server#25244)\n- Also use storage copy when dav copying directories (server#25261)\n- Silence log message (server#25263)\n- Extend ILDAPProvider to allow reading arbitrairy ldap attributes for users (server#25276)\n- Do not obtain userFolder of a federated user (server#25278)\n- Bump pear/archive_tar from 1.4.11 to 1.4.12 (3rdparty#603)\n- Add gitignore entry for .github folder of dependencies (3rdparty#604)\n- Clear event array on getting them (activity#551)\n\nUpdate to 20.0.5\n\n- Don't log params of imagecreatefromstring (server#24546)\n- Use storage copy implementation when doing dav copy\n  (server#24590)\n- Use in objectstore copy (server#24592)\n- Add tel, note, org and title search (server#24697)\n- Check php compatibility of app store app releases\n  (server#24698)\n- Fix #24682]: ensure federation cloud id is retruned if FN\n  property not found (server#24709)\n- Do not include non-required scripts on the upgrade page\n  (server#24714)\n- LDAP: fix inGroup for memberUid type of group memberships\n  (server#24716)\n- Cancel user search requests to avoid duplicate results being\n  added (server#24728)\n- Also unset the other possible unused paramters (server#24751)\n- Enables the file name check also to match name of mountpoints\n  (server#24760)\n- Fixes sharing to group ids with characters that are being url\n  encoded (server#24763)\n- Limit getIncomplete query to one row (server#24791)\n- Fix Argon2 descriptions (server#24792)\n- Actually set the TTL on redis set (server#24798)\n- Allow to force rename a conflicting calendar (server#24806)\n- Fix IPv6 localhost regex (server#24823)\n- Catch the error on heartbeat update (server#24826)\n- Make oc_files_trash.auto_id a bigint (server#24853)\n- Fix total upload size overwritten by next upload (server#24854)\n- Avoid huge exception argument logging (server#24876)\n- Make share results distinguishable if there are more than one\n  with the exact same display name (server#24878)\n- Add migration for oc_share_external columns (server#24963)\n- Don't throw a 500 when importing a broken ics reminder file\n  (server#24972)\n- Fix unreliable ViewTest (server#24976)\n- Update root.crl due to revocation of transmission.crt\n  (server#24990)\n- Set the JSCombiner cache if needed (server#24997)\n- Fix column name to check prior to deleting (server#25009)\n- Catch throwable instead of exception (server#25013)\n- Set the user language when adding the footer (server#25019)\n- Change defaultapp in config.sample.php to dashboard to improve\n  docs and align it to source code (server#25030)\n- Fix clearing the label of a share (server#25035)\n- Update psalm-baseline.xml (server#25066)\n- Don't remove assignable column for now (server#25074)\n- Add setup check to verify that the used DB version is still\n  supported… (server#25076)\n- Correctly set the user for activity parsing when preparing\n  a notifica… (activity#542)\n- Bump vue-virtual-grid from 2.2.1 to 2.3.0 (photos#597)\n- Catch possible database exceptions when fetching document data\n  (text#1221)\n- Make sure we have the proper PHP version installed before\n  running composer (text#1234)\n- Revert removal of transformResponse (text#1235)\n- Bump prosemirror-view from 1.16.1 to 1.16.5 (text#1255)\n- Bump @babel/preset-env from 7.12.1 to 7.12.11 (text#1257)\n- Bump babel-loader from 8.1.0 to 8.2.2 (text#1259)\n- Bump eslint-plugin-standard from 4.0.2 to 4.1.0 (text#1261)\n- Bump vue-loader from 15.9.5 to 15.9.6 (text#1263)\n- Bump prosemirror-model from 1.12.0 to 1.13.1 (text#1265)\n- Bump core-js from 3.7.0 to 3.8.1 (text#1266)\n- Bump stylelint from 13.7.2 to 13.8.0 (text#1269)\n- Bump @babel/plugin-transform-runtime from 7.12.1 to 7.12.10\n  (text#1271)\n- Bump sass-loader from 10.0.5 to 10.1.0 (text#1273)\n- Bump webpack-merge from 5.3.0 to 5.7.2 (text#1274)\n- Bump @babel/core from 7.12.3 to 7.12.10 (text#1277)\n- Bump cypress from 5.1.0 to 5.6.0 (text#1278)\n- Bump @vue/test-utils from 1.1.1 to 1.1.2 (text#1279)\n- Bump webpack-merge from 5.7.2 to 5.7.3 (text#1303)\n\n- The apache subpackage must require the main package, otherwise it\n  will not be uninstalled when the main package is uninstalled.\n\nUpdate to 20.0.4\n\n- Avoid dashboard crash when accessibility app is not installed (server#24636)\n- Bump ini from 1.3.5 to 1.3.7 (server#24649)\n- Handle owncloud migration to latest release (server#24653)\n- Use string for storing a OCM remote id (server#24654)\n- Fix MySQL database size calculation (serverinfo#262)\n- Bump cypress-io/github-action@v2 (viewer#722)\n- Fix] sidebar opening animation (viewer#723)\n- Fix not.exist cypress and TESTING checks (viewer#725)\n\n- Put apache configuration files in separate subpackage.\n\n- Use apache-rpm-macros for SUSE.\n- Change oc_* macros to nc_* macros.\n- Insert macro apache_serverroot also in cron files.\n\nUpdate to 20.0.3\n\n* Check quota of subdirectories when uploading to them (server#24181)\n* CircleId too short in some request (server#24196)\n* Missing level in ScopedPsrLogger (server#24212)\n* Fix nextcloud logo in email notifications misalignment (server#24228)\n* Allow selecting multiple columns with SELECT DISTINCT (server#24230)\n* Use file name instead of path in 'not allowed to share' message (server#24231)\n* Fix setting images through occ for theming (server#24232)\n* Use regex when searching on single file shares (server#24239)\n* Harden EncryptionLegacyCipher a bit (server#24249)\n* Update ScanLegacyFormat.php (server#24258)\n* Simple typo in comments (server#24259)\n* Use correct year for generated birthdays events (server#24263)\n* Delete files that exceed trashbin size immediately (server#24297)\n* Update sabre/xml to fix XML parsing errors (server#24311)\n* Only check path for being accessible when the storage is a object home (server#24325)\n* Avoid empty null default with value that will be inserted anyways (server#24333)\n* Fix contacts menu position and show uid as a tooltip (server#24342)\n* Fix the config key on the sharing expire checkbox (server#24346)\n* Set the display name of federated sharees from addressbook (server#24353)\n* Catch storage not available in versions expire command (server#24367)\n* Use proper bundles for files client and fileinfo (server#24377)\n* Properly encode path when fetching inherited shares (server#24387)\n* Formatting remote sharer should take protocol, path into account (server#24391)\n* Make sure we add new line between vcf groups exports (server#24443)\n* Fix public calendars shared to circles (server#24446)\n* Store scss variables under a different prefix for each theming config version (server#24453)\n* External storages: save group ids not display names in configuration (server#24455)\n* Use correct l10n source in files_sharing JS code (server#24462)\n* Set frame-ancestors to none if none are filled (server#24477)\n* Move the password fiels of chaging passwords to post (server#24478)\n* Move the global password for files external to post (server#24479)\n* Only attempt to move to trash if a file is not in appdata (server#24483)\n* Fix loading mtime of new file in conflict dialog in firefox (server#24491)\n* Harden setup check for TLS version if host is not reachable (server#24502)\n* Fix file size computation on 32bit platforms (server#24509)\n* Allow subscription to indicate that a userlimit is reached (server#24511)\n* Set mountid for personal external storage mounts (server#24513)\n* Only execute plain mimetype check for directories and do the fallback… (server#24517)\n* Fix vsprint parameter (server#24527)\n* Replace abandoned log normalizer with our fork (server#24530)\n* Add icon to user limit notification (server#24531)\n* Also run repair steps when encryption is disabled but a legacy key is present (server#24532)\n* [3rdparty][security] Archive TAR to 1.4.11 (server#24534)\n* Generate a new session id if the decrypting the session data fails (server#24553)\n* Revert 'Do not read certificate bundle from data dir by default' (server#24556)\n* Dont use system composer for autoload checker (server#24557)\n* Remember me is not an app_password (server#24563)\n* Do not load nonexisting setup.js (server#24582)\n* Update sabre/xml to fix XML parsing errors (3rdparty#529)\n* Use composer v1 on CI (3rdparty#532)\n* Bump pear/archive_tar from 1.4.9 to 1.4.11 (3rdparty#536)\n* Replace abandoned log normalizer with our fork (3rdparty#543)\n* Allow nullable values as subject params (activity#535)\n* Don't log when unknown array is null (notifications#803)\n* Feat/virtual grid (photos#550)\n* Make sure we have a string to localecompare to (photos#583)\n* Always get recommendations for dashboard if enabled (recommendations#336)\n* Properly fetch oracle database information (serverinfo#258)\n* Also register to urlChanged event to update RichWorkspace (text#1181)\n* Move away from GET (text#1214)\n\nUpdate to 20.0.2\n   \n* CVE-2020-8293: Fixed input validation which allowed users to store unlimited \n  data in workflow rules (boo#1181445). \n* CVE-2020-8294: Fixed a missing link validation (boo#1181803).\n* Inidicate preview availability in share api responses (server#23419)\n* CalDavBackend: check if timerange is array before accessing (server#23563)\n* Some emojis are in CHAR_CATEGORY_GENERAL_OTHER_TYPES (server#23575)\n* Also expire share type email (server#23583)\n* Only use index of mount point when it is there (server#23611)\n* Only retry fetching app store data once every 5 minutes in case it fails (server#23633)\n* Bring back the restore share button (server#23636)\n* Fix updates of NULL appconfig values (server#23641)\n* Fix sharing input placeholder for emails (server#23646)\n* Use bigint for fileid in filecache_extended (server#23690)\n* Enable theming background transparency (server#23699)\n* Fix sharer flag on ldap:show-remnants when user owned more than a single share (server#23702)\n* Make sure the function signatures of the backgroundjob match (server#23710)\n* Check if array elements exist before using them (server#23713)\n* Fix default quota display value in user row (server#23726)\n* Use lib instead if core as l10n module in OC_Files (server#23727)\n* Specify accept argument to avatar upload input field (server#23732)\n* Save email as lower case (server#23733)\n* Reset avatar cropper before showing (server#23736)\n* Also run the SabreAuthInitEvent for the main server (server#23745)\n* Type the \\OCP\\IUserManager::callForAllUsers closure with Psalm (server#23749)\n* Type the \\OCP\\AppFramework\\Services\\IInitialState::provideLazyInitial… (server#23751)\n* Don't overwrite the event if we use it later (server#23753)\n* Inform the user when flow config data exceeds thresholds (server#23759)\n* Type the \\OCP\\IUserManager::callForSeenUsers closure with Psalm (server#23763)\n* Catch errors when closing file conflict dialog (server#23774)\n* Document the backend registered events of LDAP (server#23779)\n* Fetch the logger and system config once for all query builder instances (server#23787)\n* Type the event dispatcher listener callables with Psalm (server#23789)\n* Only run phpunit when 'php' changed (server#23794)\n* Remove bold font-weight and lower font-size for empty search box (server#23829)\n* No need to check if there is an avatar available, because it is gener… (server#23846)\n* Ensure filepicker list is empty before populating (server#23850)\n* UserStatus: clear status message if message is null (server#23858)\n* Fix grid view toggle in tags view (server#23874)\n* Restrict query when searching for versions of trashbin files (server#23884)\n* Fix potentially passing null to events where IUser is expected (server#23894)\n* Make user status styles scoped (server#23899)\n* Move help to separate stylesheet (server#23900)\n* Add default font size (server#23902)\n* Do not emit UserCreatedEvent twice (server#23917)\n* Bearer must be in the start of the auth header (server#23924)\n* Fix casting of integer and boolean on Oracle (server#23935)\n* Skip already loaded apps in loadApps (server#23948)\n* Fix repair mimetype step to not leave stray cursors (server#23950)\n* Improve query type detection (server#23951)\n* Fix iLike() falsely turning escaped % and _ into wildcards (server#23954)\n* Replace some usages of OC_DB in OC\\Share\\* with query builder (server#23955)\n* Use query builder instead of OC_DB in trashbin (server#23971)\n* Fix greatest/least order for oracle (server#23975)\n* Fix link share label placeholder not showing (server#23992)\n* Unlock when promoting to exclusive lock fails (server#23995)\n* Make sure root storage is valid before checking its size (server#23996)\n* Use query builder instead of OC_DB in OC\\Files\\* (server#23998)\n* Shortcut to avoid file system setup when generating the logo URL (server#24001)\n* Remove old legacy scripts references (server#24004)\n* Fix js search in undefined ocs response (server#24012)\n* Don't leave cursors open (server#24033)\n* Fix sharing tab state not matching resharing admin settings (server#24044)\n* Run unit tests against oracle (server#24049)\n* Use png icons in caldav reminder emails (server#24050)\n* Manually iterate over calendardata when oracle is used (server#24058)\n* Make is_user_defined nullable so we can store false on oracle (server#24079)\n* Fix default internal expiration date enforce (server#24081)\n* Register new command db:add-missing-primary-keys (server#24106)\n* Convert the card resource to a string if necessary (server#24114)\n* Don't throw on SHOW VERSION query (server#24147)\n* Bump dompurify to 2.2.2 (server#24153)\n* Set up FS before querying storage info in settings (server#24156)\n* Fix default internal expiration date (server#24159)\n* CircleId too short in some request (server#24178)\n* Revert 'circleId too short in some request' (server#24183)\n* Missing level in ScopedPsrLogger (server#24212)\n* Fix activity spinner on empty activity (activity#523)\n* Add OCI github action (activity#528)\n* Disable download button by default (files_pdfviewer#257)\n* Feat/dependabot ga/stable20 (firstrunwizard#442)\n* Fix loading notifications without a message on oracle (notifications#796)\n* Do not setup appdata in constructor to avoid errors causing the whole instance to stop working (text#1105)\n* Bump eslint-plugin-standard from 4.0.1 to 4.0.2 (text#1125)\n* Bump sass-loader from 10.0.1 to 10.0.5 (text#1134)\n* Bump webpack from 4.44.1 to 4.44.2 (text#1140)\n* Bump dependencies to version in range (text#1164)\n* Validate link on click (text#1166)\n* Add migration to fix oracle issues with the database schema (text#1177)\n* Bump cypress from 4.12.1 to 5.1.0 (text#1179)\n* Fix URL escaping of shared files (viewer#681)\n* Fix component click outside and cleanup structure (viewer#684)\n\nUpdate to 20.0.1\n\nNo changelog from upstream at this time.\n\nUpdate to 20.0.0\n\n* Changes\n  The three biggest features we introduce with Nextcloud 20 are:\n  - Our new dashboard provides a great starting point for the day\n    with over a dozen widgets ranging from Twitter and Github to \n    Moodle and Zammad already available\n  - Search was unified, bringing search results of Nextcloud apps\n    as well as external services like Gitlab, Jira and Discourse\n    in one place\n  - Talk introduced bridging to other platforms including MS Teams,\n    Slack, IRC, Matrix and a dozen others\n  * Some other improvements we want to highlight include:\n    - Notifications and Activities were brought together, making \n      sure you won’t miss anything important\n    - We added a ‘status’ setting so you can communicate to other\n      users what you are up to\n    - Talk also brings dashboard and search integration, emoji picker,\n      upload view, camera and microphone settings, mute and more\n    - Calendar integrates in dashboard and search, introduced a list \n      view and design improvements\n    - Mail introduces threaded view, mailbox management and more\n    - Deck integrates with dashboard and search, introduces Calendar\n      integration, modal view for card editing and series of smaller \n      improvements\n    - Flow adds push notification and webhooks so other web apps\n      can easily integrate with Nextcloud\n    - Text introduced direct linking to files in Nextcloud\n    - Files lets you add a description to public link shares\n+ Read the full announcement on our blog\n- NC-SA-2020-037\n- CVE-2020-8295: Fixed Denial of service attack when resetting the password for a user(boo#1181804)\n- Update to 20.0.11\n- Fix boo#1188247 - CVE-2021-32678: OCS API response ratelimits are not applied\n- Fix boo#1188248 - CVE-2021-32679: filenames where not escaped by default in controllers using DownloadResponse\n- Fix boo#1188249 - CVE-2021-32680: share expiration date wasn't properly logged\n- Fix boo#1188250 - CVE-2021-32688: lacking permission check with application specific tokens\n- Fix boo#1188251 - CVE-2021-32703: lack of ratelimiting on the shareinfo endpoint\n- Fix boo#1188252 - CVE-2021-32705: lack of ratelimiting on the public DAV endpoint\n- Fix boo#1188253 - CVE-2021-32725: default share permissions were not being respected for federated reshares of files and folders\n- Fix boo#1188254 - CVE-2021-32726: webauthn tokens were not deleted after a user has been deleted\n- Fix boo#1188255 - CVE-2021-32734: possible full path disclosure on shared files\n- Fix boo#1188256 - CVE-2021-32741: lack of ratelimiting on the public share link mount endpoint\n- Bump handlebars from 4.7.6 to 4.7.7 (server#26900)\n- Bump lodash from 4.17.20 to 4.17.21 (server#26909)\n- Bump hosted-git-info from 2.8.8 to 2.8.9 (server#26920)\n- Don't break OCC if an app is breaking in it's Application class (server#26954)\n- Add bruteforce protection to the shareinfo endpoint (server#26956)\n- Ignore readonly flag for directories (server#26965)\n- Throttle MountPublicLinkController when share is not found (server#26971)\n- Respect default share permissions for federated reshares (server#27001)\n- Harden apptoken check (server#27014)\n- Use parent wrapper to properly handle moves on the same source/target storage (server#27016)\n- Fix error when using CORS with no auth credentials (server#27027)\n- Fix return value of getStorageInfo when 'quota_include_external_storage' is enabled (server#27108)\n- Bump patch dependencies (server#27183)\n- Use noreply@ as email address for share emails (server#27209)\n- Bump p-queue from 6.6.1 to 6.6.2 (server#27226)\n- Bump browserslist from 4.14.0 to 4.16.6 (server#27247)\n- Bump webpack from 4.44.1 to 4.44.2 (server#27297)\n- Properly use limit and offset for search in Jail wrapper (server#27308)\n- Make user:report command scale (server#27319)\n- Properly log expiration date removal in audit log (server#27325)\n- Propagate throttling on OCS response (server#27337)\n- Set umask before operations that create local files (server#27349)\n- Escape filename in Content-Disposition (server#27360)\n- Don't update statuses to offline again and again (server#27412)\n- Header must contain a colon (server#27456)\n- Activate constraint check for oracle / pqsql also for 20 (server#27523)\n- Only allow removing existing shares that would not be allowed due to reshare restrictions (server#27552)\n- Bump ws from 7.3.1 to 7.5.0 (server#27570)\n- Properly cleanup entries of WebAuthn on user deletion (server#27596)\n- Throttle on public DAV endpoint (server#27617)\n- Bump vue-loader from 15.9.3 to 15.9.7 (server#27639)\n- Bump eslint-plugin-standard from 4.0.1 to 4.0.2 (server#27651)\n- Validate the theming color also on CLI (server#27680)\n- Downstream encryption:fix-encrypted-version for repairing bad signature errors (server#27728)\n- Remove encodeURI code (files_pdfviewer#396)\n- Only ask for permissions on HTTPS (notifications#998)\n- Fix sorting if one of the file name is only composed with number (photos#785)\n- Backport 20 fix Photos not shown in large browser windows #630 (#686) (photos#810)\n- Update File.vue (photos#813)\n- Update chart.js (serverinfo#309)\n- Only return workspace property for top node in a propfind request (text#1611)\n- ViewerComponent: pass on autofocus to EditorWrapper (text#1647)\n- Use text/plain as content type for fetching the document (text#1692)\n- Log exceptions that happen on unknown exception and return generic messages (text#1698)\n- Add fixup (viewer#924)\n- Fix: fullscreen for Firefox (viewer#929)\n","modified":"2026-02-04T02:43:35.349683Z","published":"2021-07-20T19:21:54Z","related":["CVE-2020-8293","CVE-2020-8294","CVE-2020-8295","CVE-2021-32678","CVE-2021-32679","CVE-2021-32680","CVE-2021-32688","CVE-2021-32703","CVE-2021-32705","CVE-2021-32725","CVE-2021-32726","CVE-2021-32734","CVE-2021-32741"],"upstream":["CVE-2020-8293","CVE-2020-8294","CVE-2020-8295","CVE-2021-32678","CVE-2021-32679","CVE-2021-32680","CVE-2021-32688","CVE-2021-32703","CVE-2021-32705","CVE-2021-32725","CVE-2021-32726","CVE-2021-32734","CVE-2021-32741"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XBA6BUWCG7GXG6XVXJPYJLSFVWJRSYU7/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181445"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181803"},{"type":"REPORT","url":"https://bugzilla.suse.com/1181804"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188247"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188248"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188249"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188250"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188251"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188252"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188253"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188254"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188255"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188256"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8293"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8294"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-8295"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32678"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32679"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32680"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32688"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32703"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32705"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32726"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32734"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-32741"}],"affected":[{"package":{"name":"nextcloud","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.0.11-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nextcloud-apache":"20.0.11-bp153.2.3.1","nextcloud":"20.0.11-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1068-1.json"}},{"package":{"name":"nextcloud","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.0.11-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nextcloud-apache":"20.0.11-bp153.2.3.1","nextcloud":"20.0.11-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1068-1.json"}},{"package":{"name":"nextcloud","ecosystem":"SUSE:Package Hub 15 SP2","purl":"pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.0.11-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nextcloud":"20.0.11-bp153.2.3.1","nextcloud-apache":"20.0.11-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1068-1.json"}},{"package":{"name":"nextcloud","ecosystem":"SUSE:Package Hub 15 SP3","purl":"pkg:rpm/suse/nextcloud&distro=SUSE%20Package%20Hub%2015%20SP3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.0.11-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nextcloud-apache":"20.0.11-bp153.2.3.1","nextcloud":"20.0.11-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1068-1.json"}},{"package":{"name":"nextcloud","ecosystem":"openSUSE:Leap 15.2","purl":"pkg:rpm/opensuse/nextcloud&distro=openSUSE%20Leap%2015.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.0.11-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nextcloud":"20.0.11-bp153.2.3.1","nextcloud-apache":"20.0.11-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1068-1.json"}},{"package":{"name":"nextcloud","ecosystem":"openSUSE:Leap 15.3","purl":"pkg:rpm/opensuse/nextcloud&distro=openSUSE%20Leap%2015.3"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"20.0.11-bp153.2.3.1"}]}],"ecosystem_specific":{"binaries":[{"nextcloud-apache":"20.0.11-bp153.2.3.1","nextcloud":"20.0.11-bp153.2.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:1068-1.json"}}],"schema_version":"1.7.3"}