Home

Description

Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.

PUBLISHED Reserved 2024-11-11 | Published 2024-11-15 | Updated 2024-11-15 | Assigner GitHub_M




MEDIUM: 5.7CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H

Problem types

CWE-400: Uncontrolled Resource Consumption

Product status

>= 28.0.0, < 28.0.10
affected

>= 29.0.0, < 29.0.7
affected

References

github.com/...sories/security/advisories/GHSA-pxqf-cfxw-mqmj

github.com/nextcloud/server/pull/47627

github.com/...ommit/873c42b0f1383d5b6f2b7a481e1d9620ed30f44a

cve.org (CVE-2024-52520)

nvd.nist.gov (CVE-2024-52520)

Download JSON