CRITICAL🇵🇱 Wersja polska

CVE-2024-46958

CVSS 9.1v3.1pub. 2024-09-16upd. 2025-03-13

In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.

🤖 AI Analysis
How it works

During file synchronization between the Nextcloud server and the desktop client on Linux, the application incorrectly sets file permission bits. As a result, synchronized files may receive 'world writable' or 'world readable' permissions, i.e., accessible to every user on the operating system — regardless of who they belong to. The bug affects only the Linux client versions in the 3.13.1–3.13.3 range.

Impact

A local system user can gain unauthorized read access to other users' synchronized files (violation of confidentiality) or overwrite their contents (violation of integrity). In multi-user environments (servers, shared workstations), consequences may include leakage of sensitive data or its modification.

Mitigation & patch

Nextcloud Desktop Client should be updated to version 3.13.4, in which the issue has been fixed. Additionally, it is recommended to review permissions for synchronized files in the indicated version range and manually correct incorrect permissions (e.g., using the chmod command).

Who is affected

Nextcloud Desktop Client in versions 3.13.1, 3.13.2, and 3.13.3 running on Linux systems.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Linux Kernel

    OS
    Linux
    all versions
  • Nextcloud Desktop

    APP
    Nextcloud
    3.13.1 – 3.13.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP

CVE-2022-47986CRITICAL9.8⚠ KEVPL ✓same product

RCE przez YAML deserialization w IBM Aspera Faspex

CVE-2022-22954CRITICAL9.8⚠ KEVPL ✓same product

RCE w VMware Workspace ONE Access i Identity Manager poprzez server-side template injection

CVE-2020-4006CRITICAL9.1⚠ KEVPL ✓same product

Command Injection w VMware Workspace One Access i Identity Manager