← voltar
CVE-2024-37315

Nextcloud Server's read-only users can restore old versions

CVSS 3.5 LOWEPSS 0.4%CWE-284
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 3.5EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
14 jun 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26.0.12, 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 23.0.12.16, 24.0.12.12, 25.0.13.6, 26.0.12, 27.1.7 or 28.0.3.
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →