Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Nextcloud Server

Nextcloud Serverнабор клиент-серверных программ для создания и использования хранилища данных.

Релизный цикл, информация об уязвимостях

Продукт: Nextcloud Server
Вендор: nextcloud

График релизов

3233342025202620272028

Недавние уязвимости Nextcloud Server

Количество 456

nvd логотип

CVE-2024-52525

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 1.8
EPSS: Низкий
debian логотип

CVE-2024-52523

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. After setting ...

CVSS3: 4.6
EPSS: Низкий
nvd логотип

CVE-2024-52523

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an active session of a user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2 and Nextcloud Enterprise Server is upgraded to 25.0.13.14, 26.0.13.10, 27.1.11.10, 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 4.6
EPSS: Низкий
debian логотип

CVE-2024-52521

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. MD5 hashes we ...

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2024-52521

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not be queued for execution. By changing the Hash to SHA256 the probability was heavily decreased. It is recommended that the Nextcloud Server is upgraded to 28.0.10, 29.0.7 or 30.0.0.

CVSS3: 2.6
EPSS: Низкий
debian логотип

CVE-2024-52520

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. Due to a pre- ...

CVSS3: 5.7
EPSS: Низкий
nvd логотип

CVE-2024-52520

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

CVSS3: 5.7
EPSS: Низкий
debian логотип

CVE-2024-52519

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. The OAuth2 cl ...

CVSS3: 2.7
EPSS: Низкий
nvd логотип

CVE-2024-52519

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

CVSS3: 2.7
EPSS: Низкий
debian логотип

CVE-2024-52518

почти 2 года назад

Nextcloud Server is a self hosted personal cloud system. After an atta ...

CVSS3: 4.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
nvd логотип
CVE-2024-52525

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 1.8
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-52523

Nextcloud Server is a self hosted personal cloud system. After setting ...

CVSS3: 4.6
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-52523

Nextcloud Server is a self hosted personal cloud system. After setting up a user or administrator defined external storage with fixed credentials, the API returns them and adds them into the frontend again, allowing to read them in plain text when an attacker already has access to an active session of a user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2 and Nextcloud Enterprise Server is upgraded to 25.0.13.14, 26.0.13.10, 27.1.11.10, 28.0.12, 29.0.9 or 30.0.2.

CVSS3: 4.6
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-52521

Nextcloud Server is a self hosted personal cloud system. MD5 hashes we ...

CVSS3: 2.6
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-52521

Nextcloud Server is a self hosted personal cloud system. MD5 hashes were used to check background jobs for their uniqueness. This increased the chances of a background job with arguments falsely being identified as already existing and not be queued for execution. By changing the Hash to SHA256 the probability was heavily decreased. It is recommended that the Nextcloud Server is upgraded to 28.0.10, 29.0.7 or 30.0.0.

CVSS3: 2.6
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-52520

Nextcloud Server is a self hosted personal cloud system. Due to a pre- ...

CVSS3: 5.7
1%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-52520

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

CVSS3: 5.7
1%
Низкий
почти 2 года назад
debian логотип
CVE-2024-52519

Nextcloud Server is a self hosted personal cloud system. The OAuth2 cl ...

CVSS3: 2.7
0%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-52519

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

CVSS3: 2.7
0%
Низкий
почти 2 года назад
debian логотип
CVE-2024-52518

Nextcloud Server is a self hosted personal cloud system. After an atta ...

CVSS3: 4.4
1%
Низкий
почти 2 года назад

Уязвимостей на страницу


Поделиться