First published: Mon Sep 16 2024(Updated: )
In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Nextcloud Desktop Client | >=3.13.1<3.13.4 | |
Linux kernel |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-46958 is classified as a medium severity vulnerability affecting the Nextcloud Desktop Client due to improper file permissions.
To remediate CVE-2024-46958, upgrade the Nextcloud Desktop Client to version 3.13.4 or later.
CVE-2024-46958 affects Nextcloud Desktop Client versions 3.13.1 through 3.13.3.
CVE-2024-46958 specifically impacts the Nextcloud Desktop Client on Linux.
CVE-2024-46958 is a file permissions vulnerability that can cause synchronized files to be world writable or world readable.