The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the Nextcloud Notes app is upgraded to 4.9.3.
References
Link | Resource |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wfqv-cx85-7rjx | Third Party Advisory |
https://github.com/nextcloud/notes/pull/1260 | Patch |
https://hackerone.com/reports/2254151 | Issue Tracking |
Configurations
History
19 Aug 2024, 15:42
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.6 |
CWE | CWE-862 | |
CPE | cpe:2.3:a:nextcloud:notes:*:*:*:*:*:nextcloud:*:* | |
First Time |
Nextcloud notes
Nextcloud |
|
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wfqv-cx85-7rjx - Third Party Advisory | |
References | () https://github.com/nextcloud/notes/pull/1260 - Patch | |
References | () https://hackerone.com/reports/2254151 - Issue Tracking |
14 Jun 2024, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-06-14 16:15
Updated : 2024-08-19 15:42
NVD link : CVE-2024-37317
Mitre link : CVE-2024-37317
JSON object : View
Products Affected
nextcloud
- notes
CWE
CWE-862
Missing Authorization