Cleartext storage of sensitive information in Nextcloud Enterprise Server and Nextcloud Server - CVE-2024-52525

 

Cleartext storage of sensitive information in Nextcloud Enterprise Server and Nextcloud Server - CVE-2024-52525

Published: January 20, 2025


Vulnerability identifier: #VU103062
CSH Severity: Low
CVSS v4: 1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-52525
CWE-ID: CWE-312
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to the user password is available in memory of the PHP process. An administrator with physical access can gain access sensitive information on the target system.


Affected software

Nextcloud Enterprise Server
Nextcloud Server

How to mitigate CVE-2024-52525

Install updates from vendor's website.

Nextcloud Enterprise Server - addressed in versions 28.0.12, 29.0.9, 30.0.2
Nextcloud Server - addressed in versions 28.0.12, 29.0.9, 30.0.2

External References

Related Security Bulletins