CVE-2024-52511: Nextcloud Tables has an Authorization Bypass Through User-Controlled Key in Tables
Published Nov 15, 2024
·Updated
Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.
Affected Software
2 affected components
Nextcloud Tables<0.8.0
Nextcloud Tables Nextcloud>=0.6.0<0.8.0
Remediation
Event History
Nov 15, 2024
CVE Published
via MITRE·05:22 PM
Data Sourced
via MITRE·05:22 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-52511?
CVE-2024-52511 is considered a high severity vulnerability due to the potential for unauthorized data manipulation.
2
How do I fix CVE-2024-52511?
To fix CVE-2024-52511, upgrade Nextcloud Tables to version 0.8.0 or later.
3
What types of attacks does CVE-2024-52511 allow?
CVE-2024-52511 allows a malicious user to blindly insert new rows into tables they do not have permission to access.
4
Which versions of Nextcloud Tables are affected by CVE-2024-52511?
Versions of Nextcloud Tables prior to 0.8.0 are affected by CVE-2024-52511.
5
Who is impacted by CVE-2024-52511?
Anyone using Nextcloud Tables prior to version 0.8.0 may be impacted by CVE-2024-52511.