CVE-2024-52520

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*

History

05 Sep 2025, 00:00

Type Values Removed Values Added
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pxqf-cfxw-mqmj - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pxqf-cfxw-mqmj - Vendor Advisory
References () https://github.com/nextcloud/server/commit/873c42b0f1383d5b6f2b7a481e1d9620ed30f44a - () https://github.com/nextcloud/server/commit/873c42b0f1383d5b6f2b7a481e1d9620ed30f44a - Patch
References () https://github.com/nextcloud/server/pull/47627 - () https://github.com/nextcloud/server/pull/47627 - Patch
CPE cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*
First Time Nextcloud
Nextcloud nextcloud Server

Information

Published : 2024-11-15 17:15

Updated : 2025-09-05 00:00


NVD link : CVE-2024-52520

Mitre link : CVE-2024-52520

CVE.ORG link : CVE-2024-52520


JSON object : View

Products Affected

nextcloud

  • nextcloud_server
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')