Cleartext storage of sensitive information in Nextcloud Enterprise Server and Nextcloud Server - CVE-2024-52525
Published: January 20, 2025
Vulnerability identifier: #VU103062
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52525
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the user password is available in memory of the PHP process. An administrator with physical access can gain access sensitive information on the target system.
Affected software
Nextcloud Enterprise Server
Nextcloud Server
Nextcloud Server
How to mitigate CVE-2024-52525
Install updates from vendor's website.
Nextcloud Enterprise Server - addressed in versions 28.0.12, 29.0.9, 30.0.2
Nextcloud Server - addressed in versions 28.0.12, 29.0.9, 30.0.2
Nextcloud Server - addressed in versions 28.0.12, 29.0.9, 30.0.2