HIGH🇬🇧 English

CVE-2024-37882

CVSS 8.1v3.1pub. 2024-06-14upd. 2024-11-21

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
  • Nextcloud Server

    APP
    Nextcloud
    26.0.0 – 26.0.13 (bez)27.0.0 – 27.1.8 (bez)28.0.0 – 28.0.4 (bez)23.0.0 – 23.0.12.17 (bez)24.0.0 – 24.0.12.13 (bez)25.0.0 – 25.0.13.8 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2023-26482CRITICAL9.0PL ✓ten sam produkt

Nextcloud Server: brak walidacji scope umożliwia RCE przez workflow

CVE-2021-32802CRITICAL9.3PL ✓ten sam produkt

Nextcloud Server — SSRF, ujawnienie plików lub RCE przez podglądy obrazów

CVE-2021-22915CRITICAL9.8PL ✓ten sam produkt

Nextcloud Server — obejście ochrony brute-force przez adresy IPv6

CVE-2026-45281HIGH8.1ten sam produkt

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before...

CVE-2024-37313HIGH7.3ten sam produkt

Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the...