CVE-2024-52509

Source
https://cve.org/CVERecord?id=CVE-2024-52509
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52509.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-52509
Aliases
  • GHSA-pwpp-fvcr-w862
Published
2024-11-15T17:37:47.035Z
Modified
2026-04-02T12:23:57.210478Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N CVSS Calculator
Summary
Nextcloud Mail app does not respect download permissions in shares
Details

Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. The Nextcloud mail app incorrectly allowed attaching shared files without download permissions as attachments. This allowed users to send them the files to themselves and then downloading it from their mail clients. It is recommended that the Nextcloud Mail is upgraded to 2.2.10, 3.6.2 or 3.7.2.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-284"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52509.json"
}
References

Affected packages

Git / github.com/nextcloud/mail

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/mail
Events
Database specific
{
    "versions": [
        {
            "introduced": "2.2.0"
        },
        {
            "fixed": "2.2.10"
        }
    ]
}
Type
GIT
Repo
https://github.com/nextcloud/mail
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.6.0"
        },
        {
            "fixed": "3.6.2"
        }
    ]
}
Type
GIT
Repo
https://github.com/nextcloud/mail
Events
Database specific
{
    "versions": [
        {
            "introduced": "3.7.0"
        },
        {
            "fixed": "3.7.2"
        }
    ]
}

Affected versions

v2.*
v2.2.0
v2.2.1
v2.2.2
v2.2.3
v2.2.4
v2.2.5
v2.2.6
v2.2.7
v2.2.8
v2.2.9
v3.*
v3.6.0
v3.6.1
v3.7.0
v3.7.1

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52509.json"