Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 23 Jan 2025 15:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Nextcloud Nextcloud nextcloud Server | |
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | |
| Vendors & Products | Nextcloud Nextcloud nextcloud Server | 
Fri, 15 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Fri, 15 Nov 2024 17:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nextcloud Server is a self hosted personal cloud system. After an attacker got access to the session of a user or administrator, the attacker would be able to create, change or delete external storages without having to confirm the password. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2. | |
| Title | Nextcloud Server is missing password confirmation when changing external storage options | |
| Weaknesses | CWE-287 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-15T16:46:44.675Z
Updated: 2024-11-15T17:31:41.474Z
Reserved: 2024-11-11T18:49:23.559Z
Link: CVE-2024-52518
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-11-15T17:31:26.054Z
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-11-15T17:15:21.543
Modified: 2025-01-23T15:15:58.413
Link: CVE-2024-52518
 Redhat
                        Redhat
                    No data.