Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.
References
| Link | Resource |
|---|---|
| https://github.com/nextcloud/security-advisories/security/advisories/GHSA-rgvc-xr2w-qq45 | Vendor Advisory |
| https://github.com/nextcloud/tables/commit/13ca45f1b9f70f694aea81b78bc7416ec840c332 | Patch |
| https://github.com/nextcloud/tables/pull/1406 | Issue Tracking |
| https://hackerone.com/reports/2705507 | Issue Tracking |
Configurations
History
01 Oct 2025, 18:11
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-rgvc-xr2w-qq45 - Vendor Advisory | |
| References | () https://github.com/nextcloud/tables/commit/13ca45f1b9f70f694aea81b78bc7416ec840c332 - Patch | |
| References | () https://github.com/nextcloud/tables/pull/1406 - Issue Tracking | |
| References | () https://hackerone.com/reports/2705507 - Issue Tracking | |
| First Time |
Nextcloud tables
Nextcloud |
|
| CPE | cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:* |
Information
Published : 2024-11-15 18:15
Updated : 2025-10-01 18:11
NVD link : CVE-2024-52507
Mitre link : CVE-2024-52507
CVE.ORG link : CVE-2024-52507
JSON object : View
Products Affected
nextcloud
- tables
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
