Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3.
Metrics
Affected Vendors & Products
References
History
Thu, 08 Aug 2024 17:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Nextcloud
Nextcloud nextcloud Server |
|
Weaknesses | NVD-CWE-noinfo | |
CPEs | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* |
|
Vendors & Products |
Nextcloud
Nextcloud nextcloud Server |
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-06-14T15:36:16.181Z
Updated: 2024-09-03T16:01:08.371Z
Reserved: 2024-06-10T19:54:41.360Z
Link: CVE-2024-37884
Vulnrichment
Updated: 2024-08-02T03:57:39.918Z
NVD
Status : Modified
Published: 2024-06-14T16:15:13.340
Modified: 2024-11-21T09:24:28.007
Link: CVE-2024-37884
Redhat
No data.