Bug 2419460 (CVE-2025-66552) - CVE-2025-66552 nextcloud-server: Nextcloud Server admin_audit does not log all actions on files in groupfolders
Summary: CVE-2025-66552 nextcloud-server: Nextcloud Server admin_audit does not log al...
Keywords:
Status: NEW
Alias: CVE-2025-66552
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2420187 2420189 2420191
Blocks:
TreeView+ depends on / blocked
 
Reported: 2025-12-05 17:02 UTC by OSIDB Bzimport
Modified: 2025-12-08 21:27 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2025-12-05 17:02:16 UTC
Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1, incorrect path handling with groupfolders caused the admin_audit app to not properly log all actions on files and folders inside groupfolders. This vulnerability is fixed in Nextcloud Server and Enterprise Server prior to 30.0.9 and 31.0.1.


Note You need to log in before you can comment on or make changes to this bug.