CVE-2024-37884: Nextcloud Server's users can delete old versions of read-only shared files
Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37884?
The severity of CVE-2024-37884 is classified as high due to the impact of allowing unauthorized deletion of file versions.
How do I fix CVE-2024-37884?
To fix CVE-2024-37884, upgrade to Nextcloud Server version 26.0.12, 27.1.7, or 28.0.3.
Who is affected by CVE-2024-37884?
CVE-2024-37884 affects users of Nextcloud Server versions prior to 26.0.12, 27.1.7, or 28.0.3.
What is the exploit method for CVE-2024-37884?
CVE-2024-37884 allows a malicious user with read permissions to send delete requests for old file versions.
What are the recommended actions after identifying CVE-2024-37884?
After identifying CVE-2024-37884, it is recommended to immediately upgrade the Nextcloud Server to a patched version.