PT-2024-32299 · Nextcloud · Nextcloud Desktop Client
Nickvergessen
·
Published
2024-09-15
·
Updated
2024-09-30
·
CVE-2024-46958
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Nextcloud Desktop Client versions 3.13.1 through 3.13.3
Description
In the Nextcloud Desktop Client on Linux, synchronized files between the server and client may become world writable or world readable. This issue is fixed in version 3.13.4.
Recommendations
For versions 3.13.1 through 3.13.3, upgrade to version 3.13.4 to resolve the issue. As a temporary workaround, consider restricting access to sensitive files until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nextcloud Desktop Client