First published: Fri Jun 14 2024(Updated: )
Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | >=26.0.0<26.0.13 | |
Nextcloud Nextcloud Server | >=27.0.0<27.1.8 | |
Nextcloud Nextcloud Server | >=28.0.0<28.0.4 | |
Nextcloud Nextcloud Server | >=23.0.0<23.0.12.17 | |
Nextcloud Nextcloud Server | >=24.0.0<24.0.12.13 | |
Nextcloud Nextcloud Server | >=25.0.0<25.0.13.8 | |
Nextcloud Nextcloud Server | >=26.0.0<26.0.13 | |
Nextcloud Nextcloud Server | >=27.0.0<27.1.8 | |
Nextcloud Nextcloud Server | >=28.0.0<28.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37882 is classified as a medium severity vulnerability.
To fix CVE-2024-37882, upgrade your Nextcloud Server to version 26.0.13, 27.1.8, or 28.0.4.
CVE-2024-37882 affects owners of Nextcloud Server versions prior to 26.0.13, 27.1.8, and 28.0.4.
CVE-2024-37882 allows a recipient of a shared item to reshare it with elevated permissions.
There are no specific workarounds for CVE-2024-37882, so upgrading is strongly recommended.