Contacts search allowed users to retrieve contact information of other users beyond their contact list
Package
Server
(Nextcloud)
Affected versions
>= 31.0.0, >= 32.0.0
Patched versions
31.0.10, 32.0.1
Server
(Nextcloud Entreprise)
>= 28.0.0, >= 29.0.0, >= 30.0.0, >= 31.0.0
28.0.14.11, 29.0.16.8, 30.0.17.3, 31.0.10
Impact
Contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.
Patches
It is recommended that the Nextcloud Server is upgraded to 31.0.10 or 32.0.1
It is recommended that the Nextcloud Enterprise Server is upgraded to 28.0.14.11, 29.0.16.8, 30.0.17.3 or 31.0.10
Workarounds
References
For more information
If you have any questions or comments about this advisory: