Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.
                
            Metrics
Affected Vendors & Products
References
        History
                    Thu, 23 Jan 2025 15:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Nextcloud Nextcloud nextcloud Server | |
| CPEs | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* | |
| Vendors & Products | Nextcloud Nextcloud nextcloud Server | 
Fri, 15 Nov 2024 16:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2. | |
| Title | Nextcloud Server User password is available in memory of the PHP process | |
| Weaknesses | CWE-312 | |
| References |  | |
| Metrics | cvssV3_1 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-11-15T16:30:28.401Z
Updated: 2024-11-15T17:10:50.412Z
Reserved: 2024-11-11T18:49:23.561Z
Link: CVE-2024-52525
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Analyzed
Published: 2024-11-15T17:15:23.150
Modified: 2025-01-23T14:33:48.657
Link: CVE-2024-52525
 Redhat
                        Redhat
                    No data.