Nextcloud Server is a Nextcloud package that handles data storage. In versions prior to 19.0.13, 20.011, and 21.0.3, webauthn tokens were not deleted after a user has been deleted. If a victim reused an earlier used username, the previous user could gain access to their account. The issue was fixed in versions 19.0.13, 20.0.11, and 21.0.3. There are no known workarounds.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "19.0.13"
},
{
"introduced": "20.0.0"
},
{
"fixed": "20.0.11"
},
{
"introduced": "21.0.0"
},
{
"fixed": "21.0.3"
}
]
}