CVE-2024-37315

LOW

Nextcloud Server 23.0.0-23.0.11 and 26.0.0-26.0.11 - Authenticated Improper Access Control via File Version Restoration

Title source: llm
STIX 2.1

Description

Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26.0.12, 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 23.0.12.16, 24.0.12.12, 25.0.13.6, 26.0.12, 27.1.7 or 28.0.3.

References (3)

Core 3

Scores

CVSS v3 3.5
EPSS 0.0030
EPSS Percentile 53.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (2)
nextcloud/nextcloud_server 23.0.0 - 23.0.12
nextcloud/nextcloud_server 26.0.0 - 26.0.12
Published Jun 14, 2024
Tracked Since Feb 18, 2026