4.3
CVE-2025-66552
- EPSS 0.03%
- Veröffentlicht 05.12.2025 16:36:39
- Zuletzt bearbeitet 10.12.2025 15:14:47
- Quelle security-advisories@github.com
- CVE-Watchlists
- Unerledigt
Nextcloud Server admin_audit does not log all actions on files in groupfolders
admin_audit does not log all actions on files in groupfolders
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.
Mögliche Gegenmaßnahme
Server: * No workaround available
Enterprise Server: * No workaround available
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Nextcloud ≫ Nextcloud Server SwEdition- Version >= 30.0.0 < 30.0.9
Nextcloud ≫ Nextcloud Server SwEditionenterprise Version >= 30.0.0 < 30.0.9
Nextcloud ≫ Nextcloud Server SwEdition- Version >= 31.0.0 < 31.0.1
Nextcloud ≫ Nextcloud Server SwEditionenterprise Version >= 31.0.0 < 31.0.1
VulnDex Vulnerability Enrichment
Weitere Schwachstelleninformationen
SystemNextcloud
≫
Produkt
Server
Version
>= 30.0.0, < 30.0.9
Version
>= 31.0.0, < 31.0.1
SystemNextcloud
≫
Produkt
Enterprise Server
Version
>= 30.0.0, < 30.0.9
Version
>= 31.0.0, < 31.0.1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.03% | 0.093 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
|
| security-advisories@github.com | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
|
CWE-778 Insufficient Logging
When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.