PT-2024-27810 · Nextcloud · Nextcloud Desktop Client

Lourc0D3

·

Published

2024-06-14

·

Updated

2024-08-19

·

CVE-2024-37885

CVSS v3.1

3.8

Low

VectorAV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop Client versions prior to 3.12.0
Description A code injection issue in the Nextcloud Desktop Client for macOS allows arbitrary code to be loaded when the client is started with the DYLD INSERT LIBRARIES environment variable set. This issue affects the synchronization of files from Nextcloud Server with the user's computer.
Recommendations For versions prior to 3.12.0, upgrade the Nextcloud Desktop client to version 3.12.0 to resolve the issue. As a temporary workaround, consider restricting the use of the DYLD INSERT LIBRARIES environment variable until the upgrade is applied.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2024-37885
GHSA-4MF7-V63M-99P7

Affected Products

Nextcloud Desktop Client