Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.
Metrics
Affected Vendors & Products
References
History
Fri, 15 Nov 2024 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2. | |
Title | Nextcloud Server User password is available in memory of the PHP process | |
Weaknesses | CWE-312 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-15T16:30:28.401Z
Updated: 2024-11-15T17:10:50.412Z
Reserved: 2024-11-11T18:49:23.561Z
Link: CVE-2024-52525
Vulnrichment
No data.
NVD
Status : Awaiting Analysis
Published: 2024-11-15T17:15:23.150
Modified: 2024-11-18T17:11:56.587
Link: CVE-2024-52525
Redhat
No data.