Nextcloud Tables allows users to to create tables with individual columns. The information which Table (numeric ID) is shared with which groups and users and the respective permissions was not limited to affected users. It is recommended that the Nextcloud Tables app is upgraded to 0.8.1.
References
Link | Resource |
---|---|
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-rgvc-xr2w-qq45 | Vendor Advisory |
https://github.com/nextcloud/tables/commit/13ca45f1b9f70f694aea81b78bc7416ec840c332 | Patch |
https://github.com/nextcloud/tables/pull/1406 | Issue Tracking |
https://hackerone.com/reports/2705507 | Issue Tracking |
Configurations
History
01 Oct 2025, 18:11
Type | Values Removed | Values Added |
---|---|---|
First Time |
Nextcloud tables
Nextcloud |
|
CPE | cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:* | |
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-rgvc-xr2w-qq45 - Vendor Advisory | |
References | () https://github.com/nextcloud/tables/commit/13ca45f1b9f70f694aea81b78bc7416ec840c332 - Patch | |
References | () https://github.com/nextcloud/tables/pull/1406 - Issue Tracking | |
References | () https://hackerone.com/reports/2705507 - Issue Tracking |
18 Nov 2024, 17:11
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
15 Nov 2024, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-11-15 18:15
Updated : 2025-10-01 18:11
NVD link : CVE-2024-52507
Mitre link : CVE-2024-52507
CVE.ORG link : CVE-2024-52507
JSON object : View
Products Affected
nextcloud
- tables
CWE
CWE-639
Authorization Bypass Through User-Controlled Key