CVE-2021-37631 Details
Description
Deck is an open source kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions the Deck application didn't properly check membership of users in a Circle. This allowed other users in the instance to gain access to boards that have been shared with a Circle, even if the user was not a member of the circle. It is recommended that Nextcloud Deck is upgraded to 1.5.1, 1.4.4 or 1.2.9. If you are unable to update it is advised to disable the Deck plugin.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nextcloud/deck/pull/3217 | CVE | PatchThird Party Advisory |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4mxp-j277-82hr | CVE | Third Party Advisory |
| https://hackerone.com/reports/1256021 | CVE | Permissions RequiredThird Party Advisory |
| https://hackerone.com/reports/1280931 | CVE | Permissions RequiredThird Party Advisory |
| https://github.com/nextcloud/deck/pull/3217 | [email protected] | PatchThird Party Advisory |
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4mxp-j277-82hr | [email protected] | Third Party Advisory |
| https://hackerone.com/reports/1256021 | [email protected] | Permissions RequiredThird Party Advisory |
| https://hackerone.com/reports/1280931 | [email protected] | Permissions RequiredThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| nextcloud deck | < 1.2.9 >= 1.3.0, < 1.4.4 >= 1.5.0, < 1.5.1 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Sep 14, 2021 | Initial Analysis | [email protected] |