Skip to content

Notes app can be tricked into using a received share created before the user logged in

Moderate
nickvergessen published GHSA-wfqv-cx85-7rjx Jun 14, 2024

Package

Notes (Nextcloud)

Affected versions

>= 4.6.0

Patched versions

4.9.3

Description

Impact

If an attacker managed to share a folder called Notes/ with a newly created user before they logged in, the Notes app would use that folder store the personal notes.

Patches

It is recommended that the Nextcloud Notes app is upgraded to 4.9.3

Workarounds

  • Disable Notes app

References

For more information

If you have any questions or comments about this advisory:

Severity

Moderate
4.6
/ 10

CVSS base metrics

Attack vector
Network
Attack complexity
High
Privileges required
Low
User interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

CVE ID

CVE-2024-37317

Weaknesses

Credits