CVE-2024-52507: Share information of the Nextcloud Tables app is not limited to affected users
Published Nov 15, 2024
·Updated
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.
Affected Software
2 affected components
Nextcloud Tables<0.8.1
Nextcloud Tables Nextcloud>=0.3.0<0.8.1
Remediation
Event History
Nov 15, 2024
CVE Published
via MITRE·05:24 PM
Data Sourced
via MITRE·05:24 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52507?
CVE-2024-52507 has a high severity rating due to improper permissions management in Nextcloud Tables.
2
How do I fix CVE-2024-52507?
To fix CVE-2024-52507, upgrade the Nextcloud Tables app to version 0.8.1 or later.
3
What software is affected by CVE-2024-52507?
CVE-2024-52507 affects Nextcloud Tables version 0.8.0 and earlier.
4
What impact does CVE-2024-52507 have on users?
CVE-2024-52507 can lead to unauthorized access to table permissions by users who should not see that information.
5
When was CVE-2024-52507 disclosed?
CVE-2024-52507 was disclosed recently as part of Nextcloud's ongoing security advisories.