VulnerabilityAnalyzed
CVE-2024-52507
Nextcloud Tables allows users to to create tables with individual columns.
MEDIUM 4.3EPSS 0.42%
Does this matter?
Lower severity and a low EPSS score (0.42%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 0.42% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-639
- Affected
- nextcloud/tables
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-rgvc-xr2w-qq45Vendor Advisory
- https://github.com/nextcloud/tables/commit/13ca45f1b9f70f694aea81b78bc7416ec840c332Patch
- https://github.com/nextcloud/tables/pull/1406Issue Tracking
- https://hackerone.com/reports/2705507Issue Tracking
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.