CVE-2024-52516: Nextcloud Server's shares are not removed when user is limited to share with in their groups and being removed from one of them
Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users that are in ones own groups, after a user was removed from a group, previously shared items were not unshared. It is recommended that the Nextcloud Server is upgraded to 22.2.11 or 23.0.11 or 24.0.6 and Nextcloud Enterprise Server is upgraded to 22.2.11 or 23.0.11 or 24.0.6.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52516?
CVE-2024-52516 has a moderate severity level due to the impact on shared items when user group memberships change.
How do I fix CVE-2024-52516?
To fix CVE-2024-52516, upgrade your Nextcloud Server to a version beyond 26.0.13.9, 27.1.11.9, 28.0.9, or 29.0.5.
What versions of Nextcloud Server are affected by CVE-2024-52516?
CVE-2024-52516 affects Nextcloud Server versions from 26.0.0 to 26.0.13.9, 27.0.0 to 27.1.11.9, 28.0.0 to 28.0.9, and 29.0.0 to 29.0.5.
What is the nature of the vulnerability in CVE-2024-52516?
CVE-2024-52516 is a vulnerability that allows previously shared items to remain accessible even after a user is removed from a group.
Is there a workaround for CVE-2024-52516?
No official workaround is provided for CVE-2024-52516; the recommended action is to upgrade to a secure version.