PT-2024-9164 · Nextcloud+2 · Nextcloud Server+2

Tuyenee

·

Published

2024-10-17

·

Updated

2025-02-01

·

CVE-2024-52518

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions: Nextcloud Server versions prior to 28.0.12 Nextcloud Server versions prior to 29.0.9 Nextcloud Server versions prior to 30.0.2
Description: The issue is related to insufficient authentication procedure in Nextcloud Server, allowing an attacker with access to a user's or administrator's session to create, change, or delete external storages without confirming the password. This could potentially lead to unauthorized access.
Recommendations: For versions prior to 28.0.12, upgrade to 28.0.12 or later. For versions prior to 29.0.9, upgrade to 29.0.9 or later. For versions prior to 30.0.2, upgrade to 30.0.2 or later.

Exploit

Fix

Incorrect Authorization

Improper Authentication

Weakness Enumeration

Related Identifiers

ALT-PU-2025-1663
ALT-PU-2025-1855
ALT-PU-2025-2137
BDU:2024-10851
CVE-2024-52518
GHSA-VRHF-532W-99RG

Affected Products

Alt Linux
Nextcloud Server
Red Os