CVE-2024-37885

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*

History

19 Aug 2024, 16:10

Type Values Removed Values Added
CWE CWE-94
CPE cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
First Time Nextcloud desktop
Nextcloud
Apple
Apple macos
References () https://github.com/nextcloud/desktop/pull/6378 - () https://github.com/nextcloud/desktop/pull/6378 - Patch
References () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4mf7-v63m-99p7 - () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4mf7-v63m-99p7 - Patch, Third Party Advisory
References () https://hackerone.com/reports/2307625 - () https://hackerone.com/reports/2307625 - Issue Tracking

14 Jun 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-14 16:15

Updated : 2024-08-19 16:10


NVD link : CVE-2024-37885

Mitre link : CVE-2024-37885


JSON object : View

Products Affected

apple

  • macos

nextcloud

  • desktop
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')