CVE-2024-52507

Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*

History

01 Oct 2025, 18:11

Type Values Removed Values Added
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-rgvc-xr2w-qq45 - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-rgvc-xr2w-qq45 - Vendor Advisory
References () https://github.com/nextcloud/tables/commit/13ca45f1b9f70f694aea81b78bc7416ec840c332 - () https://github.com/nextcloud/tables/commit/13ca45f1b9f70f694aea81b78bc7416ec840c332 - Patch
References () https://github.com/nextcloud/tables/pull/1406 - () https://github.com/nextcloud/tables/pull/1406 - Issue Tracking
References () https://hackerone.com/reports/2705507 - () https://hackerone.com/reports/2705507 - Issue Tracking
First Time Nextcloud tables
Nextcloud
CPE cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*

Information

Published : 2024-11-15 18:15

Updated : 2025-10-01 18:11


NVD link : CVE-2024-52507

Mitre link : CVE-2024-52507

CVE.ORG link : CVE-2024-52507


JSON object : View

Products Affected

nextcloud

  • tables
CWE
CWE-639

Authorization Bypass Through User-Controlled Key