PT-2024-9153 · Nextcloud+2 · Nextcloud Server+2

Tuyenee

·

Published

2024-10-28

·

Updated

2025-02-01

·

CVE-2024-52525

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Nextcloud Server versions prior to 28.0.12 Nextcloud Server versions prior to 29.0.9 Nextcloud Server versions prior to 30.0.2
Description: The issue concerns the storage of user passwords in unencrypted form in session data under certain conditions. Although the session data is encrypted before being saved, a malicious process gaining access to the PHP process memory could obtain the cleartext password.
Recommendations: For versions prior to 28.0.12, upgrade to 28.0.12. For versions prior to 29.0.9, upgrade to 29.0.9. For versions prior to 30.0.2, upgrade to 30.0.2. As a temporary workaround, consider restricting access to sensitive data until the upgrade is applied.

Exploit

Fix

Cleartext Storage of Sensitive Information

Weakness Enumeration

Related Identifiers

ALT-PU-2025-1663
ALT-PU-2025-1855
ALT-PU-2025-2137
BDU:2024-10840
CVE-2024-52525
GHSA-W7V5-MGXM-V6GM

Affected Products

Alt Linux
Nextcloud Server
Red Os