CVE-2024-52513 LOW

CVE-2024-52513: Nextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Password protected" shares

Vendor Nextcloud
Product security-advisories
Weakness CWE-200 · Info exposure
Published November 15, 2024
Last update November 15, 2024

CVSS base score

2.6/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8 or 30.0.1.

Key dates

02Disclosure timeline

November 15, 2024 CVE published
November 15, 2024 Record updated