CVE-2025-66510

Source
https://cve.org/CVERecord?id=CVE-2025-66510
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66510.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-66510
Aliases
Published
2025-12-05T16:18:53.699Z
Modified
2026-08-08T03:32:26.549683815Z
Severity
  • 4.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N CVSS Calculator
Summary
Nextcloud Server Contacts Search allowed users to retrieve contact information of other users beyond their contact list
Details

Nextcloud Server is a self hosted personal cloud system. In Nextcloud Server prior to 31.0.10 and 32.0.1 and Nextcloud Enterprise Server prior to 28.0.14.11, 29.0.16.8, 30.0.17.3, and 31.0.10, contacts search allowed to retrieve personal data of other users (emails, names, identifiers) without proper access control. This allows an authenticated user to retrieve information about accounts that are not related or added as contacts.

Database specific
{
    "cwe_ids": [
        "CWE-359"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/66xxx/CVE-2025-66510.json",
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/nextcloud/server

Affected ranges

Type
GIT
Repo
https://github.com/nextcloud/server
Events
Database specific
Show details
{
    "cpe": [
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
        "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
    ],
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "31.0.0"
        },
        {
            "fixed": "31.0.10"
        },
        {
            "introduced": "32.0.0"
        },
        {
            "fixed": "32.0.1"
        }
    ]
}

Affected versions

v31.*
v31.0.0
v31.0.1
v31.0.10rc1
v31.0.10rc2
v31.0.1rc1
v31.0.1rc2
v31.0.2
v31.0.2rc1
v31.0.3
v31.0.3rc1
v31.0.3rc2
v31.0.4
v31.0.4rc1
v31.0.5
v31.0.5rc1
v31.0.6
v31.0.6rc1
v31.0.6rc2
v31.0.7
v31.0.7rc1
v31.0.8
v31.0.8rc1
v31.0.9
v31.0.9rc1
v32.*
v32.0.0
v32.0.1rc1
v32.0.1rc2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66510.json"