CVE-2024-52525

Published
View on NVD ↗
CVSS v3
1.8
LOW
CVSS v2
N/A
Affected
2
PROJECTS

Description

Nextcloud Server is a self hosted personal cloud system. Under certain conditions the password of a user was stored unencrypted in the session data. The session data is encrypted before being saved in the session storage (Redis or disk), but it would allow a malicious process that gains access to the memory of the PHP process, to get access to the cleartext password of the user. It is recommended that the Nextcloud Server is upgraded to 28.0.12, 29.0.9 or 30.0.2.

👮 Security advisories of Nextcloud
GitHubGitHub
75
☁️ Nextcloud server, a safe home for all your data
GitHubGitHub
35.9K