Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.
References
Configurations
Configuration 1 (hide)
|
History
05 Sep 2025, 00:00
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:* cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:* |
|
First Time |
Nextcloud
Nextcloud nextcloud Server |
|
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-pxqf-cfxw-mqmj - Vendor Advisory | |
References | () https://github.com/nextcloud/server/commit/873c42b0f1383d5b6f2b7a481e1d9620ed30f44a - Patch | |
References | () https://github.com/nextcloud/server/pull/47627 - Patch |
18 Nov 2024, 17:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Nov 2024, 17:35
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 |
15 Nov 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-15 17:15
Updated : 2025-09-05 00:00
NVD link : CVE-2024-52520
Mitre link : CVE-2024-52520
CVE.ORG link : CVE-2024-52520
JSON object : View
Products Affected
nextcloud
- nextcloud_server