4.3

CVE-2024-37315

Nextcloud Server's read-only users can restore old versions

Read-only users can restore old versions

Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26.0.12, 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 23.0.12.16, 24.0.12.12, 25.0.13.6, 26.0.12, 27.1.7 or 28.0.3.
Mögliche Gegenmaßnahme
Server: * Disable app files_version
Enterprise Server: * Disable app files_version
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudNextcloud Server SwEditionenterprise Version >= 23.0.0 <= 23.0.12
NextcloudNextcloud Server SwEditionenterprise Version >= 24.0.0 <= 24.0.12
NextcloudNextcloud Server SwEditionenterprise Version >= 25.0.0 < 25.0.13
NextcloudNextcloud Server SwEdition- Version >= 26.0.0 < 26.0.12
NextcloudNextcloud Server SwEditionenterprise Version >= 26.0.0 < 26.0.12
NextcloudNextcloud Server SwEdition- Version >= 27.0.0 < 27.1.7
NextcloudNextcloud Server SwEditionenterprise Version >= 27.0.0 < 27.1.7
NextcloudNextcloud Server SwEdition- Version >= 28.0.0 < 28.0.3
NextcloudNextcloud Server SwEditionenterprise Version >= 28.0.0 < 28.0.3
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemNextcloud
Produkt Server
Version >= 26.0.0, < 26.0.12
Version >= 27.0.0, < 27.1.7
Version >= 28.0.0, < 28.0.3
SystemNextcloud
Produkt Enterprise Server
Version >= 23.0.0, < 23.0.12.16
Version >= 24.0.0, < 24.0.12.12
Version >= 25.0.0, < 25.0.13.6
Version >= 26.0.0, < 26.0.12
Version >= 27.0.0, < 27.1.7
Version >= 28.0.0, < 28.0.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.3% 0.53
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
security-advisories@github.com 3.5 2.1 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.