HomeNextcloudCVE-2024-37317

CVE-2024-37317

MEDIUM
4.6CVSS
Published: 2024-06-14
Updated: 2024-11-21
AI Analysis

Description

The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the Nextcloud Notes app is upgraded to 4.9.3.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Attack Vector
network
Complexity
high
Privileges
low
User Action
required
Scope
unchanged
Confidentiality
low
Integrity
low
Availability
low
Weaknesses
CWE-284CWE-862

Metadata

Primary Vendor
NEXTCLOUD
Published
6/14/2024
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

nextcloud : notes

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2024-37317 | MEDIUM Severity | CVEDatabase.com | CVEDatabase.com