Bug 2292810 (CVE-2024-37882, CVE-2024-37883, CVE-2024-37884, CVE-2024-37885, CVE-2024-37886, CVE-2024-37887)

Summary: CVE-2024-37882 CVE-2024-37883 CVE-2024-37884 CVE-2024-37885 CVE-2024-37886 CVE-2024-37887 nextcloud: multiple vulnerabilities
Product: [Other] Security Response Reporter: Patrick Del Bello <pdelbell>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedKeywords: Security
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2292812, 2292811, 2292813, 2292814, 2292815, 2292816    
Bug Blocks:    

Description Patrick Del Bello 2024-06-18 03:17:03 UTC
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h4xv-cjpm-j595
https://github.com/nextcloud/server/pull/45309
https://hackerone.com/reports/2479325

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3.0.0, 4.0.0 or 5.0.0.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vw5h-29xf-g55g
https://github.com/nextcloud/user_oidc/pull/715
https://hackerone.com/reports/1878391

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.

https://github.com/nextcloud/desktop/pull/6378
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4mf7-v63m-99p7
https://hackerone.com/reports/2307625

Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xwgx-f37p-xh8c
https://github.com/nextcloud/server/pull/43727
https://hackerone.com/reports/2290680

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is recommended that the Nextcloud Deck app is upgraded to 1.6.6 or 1.7.5 or 1.8.7 or 1.9.6 or 1.11.3 or 1.12.1.

https://github.com/nextcloud/deck/pull/5423
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x45g-vx69-r9m8
https://hackerone.com/reports/2289333

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jjm3-j9xh-5xmq
https://github.com/nextcloud/server/pull/44339
https://hackerone.com/reports/2289425

Comment 1 Patrick Del Bello 2024-06-18 03:19:26 UTC
Created nextcloud tracking bugs for this issue:

Affects: fedora-all [bug 2292811]


Created nextcloud-client tracking bugs for this issue:

Affects: epel-all [bug 2292812]
Affects: fedora-all [bug 2292816]


Created nextcloud:23/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2292813]


Created nextcloud:24/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2292814]


Created nextcloud:nextcloud-22/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2292815]