CVE-2024-52520: Nextcloud Server's link reference provider can be tricked into downloading bigger files than intended
Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52520?
The severity of CVE-2024-52520 is considered moderate due to the potential for excessive resource consumption.
How do I fix CVE-2024-52520?
To fix CVE-2024-52520, upgrade your Nextcloud Server to version 28.0.10 or higher.
Which versions of Nextcloud are affected by CVE-2024-52520?
CVE-2024-52520 affects Nextcloud Server versions before 28.0.10 and 29.0.7, as well as Nextcloud Enterprise Server versions before 27.1.11.8.
What is the impact of CVE-2024-52520?
The impact of CVE-2024-52520 can lead to denial of service due to excessive data retrieval based on the pre-flighted HEAD request.
Is there a workaround for CVE-2024-52520?
Currently, the recommended mitigation for CVE-2024-52520 is to upgrade to the latest version, as there are no known workarounds.