Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and then downloading it from their mail clients. It is recommended that the Nextcloud Mail is upgraded to 2.2.10, 3.6.2 or 3.7.2.
References
Link | Resource |
---|---|
https://github.com/nextcloud/mail/commit/8d44f1ce44684022aa4e62a3e0462fdadcde6c8b | Patch |
https://github.com/nextcloud/mail/pull/9592 | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pwpp-fvcr-w862 | Patch Vendor Advisory |
https://hackerone.com/reports/1878255 | Issue Tracking |
Configurations
Configuration 1 (hide)
|
History
04 Sep 2025, 23:55
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:nextcloud:mail:*:*:*:*:*:nextcloud:*:* | |
CWE | NVD-CWE-noinfo | |
References | () https://github.com/nextcloud/mail/commit/8d44f1ce44684022aa4e62a3e0462fdadcde6c8b - Patch | |
References | () https://github.com/nextcloud/mail/pull/9592 - Patch | |
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pwpp-fvcr-w862 - Patch, Vendor Advisory | |
References | () https://hackerone.com/reports/1878255 - Issue Tracking | |
First Time |
Nextcloud
Nextcloud mail |
18 Nov 2024, 17:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Nov 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-15 18:15
Updated : 2025-09-04 23:55
NVD link : CVE-2024-52509
Mitre link : CVE-2024-52509
CVE.ORG link : CVE-2024-52509
JSON object : View
Products Affected
nextcloud
CWE