PT-2024-32299 · Nextcloud · Nextcloud Desktop Client

Nickvergessen

·

Published

2024-09-15

·

Updated

2024-09-30

·

CVE-2024-46958

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Desktop Client versions 3.13.1 through 3.13.3
Description In the Nextcloud Desktop Client on Linux, synchronized files between the server and client may become world writable or world readable. This issue is fixed in version 3.13.4.
Recommendations For versions 3.13.1 through 3.13.3, upgrade to version 3.13.4 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2024-46958

Affected Products

Nextcloud Desktop Client