PT-2024-4412 · Nextcloud+1 · Nextcloud Notes+1

Arianitisufi

+2

·

Published

2024-06-14

·

Updated

2024-08-19

·

CVE-2024-37317

CVSS v2.0

4.6

Medium

VectorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Nextcloud Notes versions prior to 4.9.3
Description The issue is related to the possibility of sharing a folder called Notes/ with a newly created user before they log in, allowing a remote attacker to access confidential information.
Recommendations For versions prior to 4.9.3, upgrade the Nextcloud Notes app to version 4.9.3 to resolve the issue. As a temporary workaround, consider restricting access to the Notes/ folder to minimize the risk of exploitation.

Exploit

Fix

Improper Access Control

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2024-04911
CVE-2024-37317
GHSA-WFQV-CX85-7RJX

Affected Products

Nextcloud Notes
Red Os