CVE-2024-52513
Nextcloud Server is a self hosted personal cloud system. After receiving a "Files drop" or "Password protected" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8 or 30.0.1.
- Affected products
- Alt Linux, Nextcloud Enterprise Server, Nextcloud Server
- Nextcloud Nextcloud Server
- < 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8, 30.0.1
- Fix
- Available
- CVSS 3.1
- 4.3 MEDIUM
- EPSS
- 0.5% (41th percentile)
- Weakness
- CWE-200
- NVD status
- Analyzed
- Published
- 2024-11-15
CVE-2024-52513 at NVD
No indexed exploits for CVE-2024-52513 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2024-52513 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.