Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, the Nextcloud Text application shipped with Nextcloud Server returned verbatim exception messages to the user. This could result in a full path disclosure on shared files. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. As a workaround, one may disable the Nextcloud Text application in Nextcloud Server app settings. References: https://github.com/nextcloud/security-advisories/security/advisories/GHSA-6hf5-c2c4-2526 https://github.com/nextcloud/text/pull/1695 https://hackerone.com/reports/1246721
Created nextcloud tracking bugs for this issue: Affects: fedora-all [bug 1988988]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.