CVE-2024-37314: Nextcloud Photos' shared albums have no restriction on photo removal
Published Jun 14, 2024
·Updated
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.
Affected Software
2 affected components
Nextcloud Server>=25.0.0<25.0.7
Nextcloud Server>=26.0.0<26.0.2
Remediation
Patch Available
Event History
Jun 14, 2024
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-37314?
CVE-2024-37314 has been classified as a medium severity vulnerability.
2
How do I fix CVE-2024-37314?
To resolve CVE-2024-37314, upgrade Nextcloud Server to version 25.0.7 or 26.0.2.
3
Which versions of Nextcloud are affected by CVE-2024-37314?
CVE-2024-37314 affects Nextcloud Server versions prior to 25.0.7 and 26.0.2.
4
Can unregistered users remove photos in Nextcloud due to CVE-2024-37314?
Yes, CVE-2024-37314 allows users to remove photos from the albums of registered users.
5
Is the Nextcloud Enterprise Server affected by CVE-2024-37314?
Yes, the Nextcloud Enterprise Server is also affected by CVE-2024-37314 and should be upgraded to 25.0.7 or 26.0.2.