Unrated severityNVD Advisory· Published Nov 15, 2024· Updated Nov 15, 2024
Nextcloud Server's link reference provider can be tricked into downloading bigger files than intended
CVE-2024-52520
Description
Nextcloud Server is a self hosted personal cloud system. Due to a pre-flighted HEAD request, the link reference provider could be tricked into downloading bigger websites than intended, to find open-graph data. It is recommended that the Nextcloud Server is upgraded to 28.0.10 or 29.0.7 and Nextcloud Enterprise Server is upgraded to 27.1.11.8, 28.0.10 or 29.0.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: >= 27.1.11.8 and < 28.0.10, >= 28.0.10 and < 29.0.7, >= 29.0.7
- nextcloud/security-advisoriesv5Range: >= 28.0.0, < 28.0.10
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/security-advisories/security/advisories/GHSA-pxqf-cfxw-mqmjmitrex_refsource_CONFIRM
- github.com/nextcloud/server/commit/873c42b0f1383d5b6f2b7a481e1d9620ed30f44amitrex_refsource_MISC
- github.com/nextcloud/server/pull/47627mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.