Nextcloud server is an open source, self hosted personal cloud. In affected versions an attacker is able to bypass Two Factor Authentication in Nextcloud. Thus knowledge of a password, or access to a WebAuthN trusted device of a user was sufficient to gain access to an account. It is recommended that the Nextcloud Server is upgraded to 20.0.12, 21.0.4 or 22.1.0. There are no workaround for this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| nextcloud / nextcloud_server | 21.0.0 | 21.0.4 |
| nextcloud / nextcloud_server | 22.0.0 | 22.1.0 |
| nextcloud / nextcloud_server | - | 20.0.12 |