First published: Fri Jun 14 2024(Updated: )
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Nextcloud Server | >=27.0.0<27.1.10 | |
Nextcloud Nextcloud Server | >=27.0.0<27.1.10 | |
Nextcloud Nextcloud Server | >=28.0.0<=28.0.6 | |
Nextcloud Nextcloud Server | >=28.0.0<28.0.6 | |
Nextcloud Nextcloud Server | =29.0.0 | |
Nextcloud Nextcloud Server | =29.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37887 has been classified as a moderate severity vulnerability affecting the recurrence exceptions of private shared calendar events in Nextcloud Server.
To fix CVE-2024-37887, upgrade your Nextcloud Server to versions 27.1.10, 28.0.6, or 29.0.1.
CVE-2024-37887 affects users of Nextcloud Server versions between 27.0.0 and 27.1.10, 28.0.0 and 28.0.6, and the exact version 29.0.0.
CVE-2024-37887 exposes the recurrence exceptions of private shared calendar events, which can be accessed by users who are granted share access.
Yes, Nextcloud Enterprise Server users should upgrade to version 27.1.1 or later to address CVE-2024-37887.