CVE-2024-52516 Information
Nov 16, 2024
cve
Description
Nextcloud Server is a self hosted personal cloud system. When a server is configured to only allow sharing with users that are in ones own groups after a user was removed from a group previously shared items were not unshared. It is recommended that the Nextcloud Server is upgraded to 22.2.11 or 23.0.11 or 24.0.6 and Nextcloud Enterprise Server is upgraded to 22.2.11 or 23.0.11 or 24.0.6.
Reference
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-35gc-jc6x-29cm https://github.com/nextcloud/server/pull/47180 https://github.com/nextcloud/server/commit/142b6e313ffa9d3b950bcd23cb58850d3ae7cf34
Share on: