4.3

CVE-2025-66552

Nextcloud Server admin_audit does not log all actions on files in groupfolders

admin_audit does not log all actions on files in groupfolders

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.
Mögliche Gegenmaßnahme
Server: * No workaround available
Enterprise Server: * No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
NextcloudNextcloud Server SwEdition- Version >= 30.0.0 < 30.0.9
NextcloudNextcloud Server SwEditionenterprise Version >= 30.0.0 < 30.0.9
NextcloudNextcloud Server SwEdition- Version >= 31.0.0 < 31.0.1
NextcloudNextcloud Server SwEditionenterprise Version >= 31.0.0 < 31.0.1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Weitere Schwachstelleninformationen
SystemNextcloud
Produkt Server
Version >= 30.0.0, < 30.0.9
Version >= 31.0.0, < 31.0.1
SystemNextcloud
Produkt Enterprise Server
Version >= 30.0.0, < 30.0.9
Version >= 31.0.0, < 31.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.093
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
security-advisories@github.com 4.3 2.8 1.4
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
CWE-778 Insufficient Logging

When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.