Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 15 Nov 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2. | |
Title | Nextcloud Server is missing password confirmation when changing external storage options | |
Weaknesses | CWE-287 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-15T16:46:44.675Z
Updated: 2024-11-15T17:31:41.474Z
Reserved: 2024-11-11T18:49:23.559Z
Link: CVE-2024-52518
Vulnrichment
Updated: 2024-11-15T17:31:26.054Z
NVD
Status : Awaiting Analysis
Published: 2024-11-15T17:15:21.543
Modified: 2024-11-18T17:11:56.587
Link: CVE-2024-52518
Redhat
No data.