Bug 2292810 (CVE-2024-37882, CVE-2024-37883, CVE-2024-37884, CVE-2024-37885, CVE-2024-37886, CVE-2024-37887) - CVE-2024-37882 CVE-2024-37883 CVE-2024-37884 CVE-2024-37885 CVE-2024-37886 CVE-2024-37887 nextcloud: multiple vulnerabilities
Summary: CVE-2024-37882 CVE-2024-37883 CVE-2024-37884 CVE-2024-37885 CVE-2024-37886 CV...
Keywords:
Status: NEW
Alias: CVE-2024-37882, CVE-2024-37883, CVE-2024-37884, CVE-2024-37885, CVE-2024-37886, CVE-2024-37887
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2292812 2292811 2292813 2292814 2292815 2292816
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-06-18 03:17 UTC by Patrick Del Bello
Modified: 2024-06-18 03:19 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Patrick Del Bello 2024-06-18 03:17:03 UTC
Nextcloud Server is a self hosted personal cloud system. Private shared calendar events' recurrence exceptions can be read by sharees. It is recommended that the Nextcloud Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1 and that the Nextcloud Enterprise Server is upgraded to 27.1.10 or 28.0.6 or 29.0.1.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-h4xv-cjpm-j595
https://github.com/nextcloud/server/pull/45309
https://hackerone.com/reports/2479325

user_oidc app is an OpenID Connect user backend for Nextcloud. An attacker could potentially trick the app into accepting a request that is not signed by the correct server. It is recommended that the Nextcloud user_oidc app is upgraded to 1.3.5, 2.0.0, 3.0.0, 4.0.0 or 5.0.0.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vw5h-29xf-g55g
https://github.com/nextcloud/user_oidc/pull/715
https://hackerone.com/reports/1878391

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.

https://github.com/nextcloud/desktop/pull/6378
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4mf7-v63m-99p7
https://hackerone.com/reports/2307625

Nextcloud Server is a self hosted personal cloud system. A malicious user was able to send delete requests for old versions of files they only got shared with read permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3 and that the Nextcloud Enterprise Server is upgraded to 26.0.12 or 27.1.7 or 28.0.3.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-xwgx-f37p-xh8c
https://github.com/nextcloud/server/pull/43727
https://hackerone.com/reports/2290680

Nextcloud Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. A user with access to a deck board was able to access comments and attachments of already deleted cards. It is recommended that the Nextcloud Deck app is upgraded to 1.6.6 or 1.7.5 or 1.8.7 or 1.9.6 or 1.11.3 or 1.12.1.

https://github.com/nextcloud/deck/pull/5423
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-x45g-vx69-r9m8
https://hackerone.com/reports/2289333

Nextcloud Server is a self hosted personal cloud system. A recipient of a share with read&share permissions could reshare the item with more permissions. It is recommended that the Nextcloud Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4 and that the Nextcloud Enterprise Server is upgraded to 26.0.13 or 27.1.8 or 28.0.4.

https://github.com/nextcloud/security-advisories/security/advisories/GHSA-jjm3-j9xh-5xmq
https://github.com/nextcloud/server/pull/44339
https://hackerone.com/reports/2289425

Comment 1 Patrick Del Bello 2024-06-18 03:19:26 UTC
Created nextcloud tracking bugs for this issue:

Affects: fedora-all [bug 2292811]


Created nextcloud-client tracking bugs for this issue:

Affects: epel-all [bug 2292812]
Affects: fedora-all [bug 2292816]


Created nextcloud:23/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2292813]


Created nextcloud:24/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2292814]


Created nextcloud:nextcloud-22/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2292815]


Note You need to log in before you can comment on or make changes to this bug.