Bug ID 1226375
Summary VUL-0: CVE-2024-37884: nextcloud: users can delete old versions of read-only shared files
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/410998/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee ecsos@schirra.net
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC camila.matos@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

Nextcloud Server is a self hosted personal cloud system. A malicious user was
able to send delete requests for old versions of files they only got shared
with read permissions. It is recommended that the Nextcloud Server is upgraded
to 26.0.12 or 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is
upgraded to 26.0.12 or 27.1.7 or 28.0.3.

References:
https://github.com/nextcloud/server/pull/43727
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-37884
https://www.cve.org/CVERecord?id=CVE-2024-37884
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xwgx-f37p-xh8c
https://hackerone.com/reports/2290680


You are receiving this mail because: