Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.
History

Fri, 15 Nov 2024 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 15 Nov 2024 17:00:00 +0000

Type Values Removed Values Added
Description Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.
Title Nextcloud Server's OAuth2 client secrets were stored in a recoverable way
Weaknesses CWE-922
References
Metrics cvssV3_1

{'score': 2.7, 'vector': 'CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-11-15T16:43:57.246Z

Updated: 2024-11-15T16:58:55.845Z

Reserved: 2024-11-11T18:49:23.559Z

Link: CVE-2024-52519

cve-icon Vulnrichment

Updated: 2024-11-15T16:58:50.818Z

cve-icon NVD

Status : Received

Published: 2024-11-15T17:15:21.843

Modified: 2024-11-15T17:15:21.843

Link: CVE-2024-52519

cve-icon Redhat

No data.