PT-2024-9164 · Nextcloud+2 · Nextcloud Server+2
Tuyenee
·
Published
2024-10-17
·
Updated
2025-02-01
·
CVE-2024-52518
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions:
Nextcloud Server versions prior to 28.0.12
Nextcloud Server versions prior to 29.0.9
Nextcloud Server versions prior to 30.0.2
Description:
The issue is related to insufficient authentication procedure in Nextcloud Server, allowing an attacker with access to a user's or administrator's session to create, change, or delete external storages without confirming the password. This could potentially lead to unauthorized access.
Recommendations:
For versions prior to 28.0.12, upgrade to 28.0.12 or later.
For versions prior to 29.0.9, upgrade to 29.0.9 or later.
For versions prior to 30.0.2, upgrade to 30.0.2 or later.
Exploit
Fix
Incorrect Authorization
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Nextcloud Server
Red Os