CVE-2024-52519

Nextcloud Server is a self hosted personal cloud system. The OAuth2 client secrets were stored in a recoverable way, so that an attacker that got access to a backup of the database and the Nextcloud config file, would be able to decrypt them. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

History

23 Jan 2025, 15:05

Type Values Removed Values Added
First Time Nextcloud nextcloud Server
Nextcloud
CPE cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fvpc-8hq6-jgq2 - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-fvpc-8hq6-jgq2 - Vendor Advisory
References () https://github.com/nextcloud/server/commit/09b8aea8f6783514bffe00df6abbf9fa542faac5 - () https://github.com/nextcloud/server/commit/09b8aea8f6783514bffe00df6abbf9fa542faac5 - Patch
References () https://github.com/nextcloud/server/pull/47635 - () https://github.com/nextcloud/server/pull/47635 - Issue Tracking

Information

Published : 2024-11-15 17:15

Updated : 2025-01-23 15:05


NVD link : CVE-2024-52519

Mitre link : CVE-2024-52519

CVE.ORG link : CVE-2024-52519


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-922

Insecure Storage of Sensitive Information