First published: Fri Jun 14 2024(Updated: )
Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | >=25.0.0<25.0.7 | |
Nextcloud Nextcloud Server | >=26.0.0<26.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37314 has been classified as a medium severity vulnerability.
To resolve CVE-2024-37314, upgrade Nextcloud Server to version 25.0.7 or 26.0.2.
CVE-2024-37314 affects Nextcloud Server versions prior to 25.0.7 and 26.0.2.
Yes, CVE-2024-37314 allows users to remove photos from the albums of registered users.
Yes, the Nextcloud Enterprise Server is also affected by CVE-2024-37314 and should be upgraded to 25.0.7 or 26.0.2.