2024-06-14 18:03:12 +00:00
{
"id" : "CVE-2024-37317" ,
"sourceIdentifier" : "security-advisories@github.com" ,
"published" : "2024-06-14T16:15:11.960" ,
2024-08-19 16:03:14 +00:00
"lastModified" : "2024-08-19T15:42:54.980" ,
"vulnStatus" : "Analyzed" ,
2024-07-14 02:06:08 +00:00
"cveTags" : [ ] ,
2024-06-14 18:03:12 +00:00
"descriptions" : [
{
"lang" : "en" ,
"value" : "The Nextcloud Notes app is a distraction free notes taking app for Nextcloud. If an attacker managed to share a folder called `Notes/` with a newly created user before they logged in, the Notes app would use that folder store the personal notes. It is recommended that the Nextcloud Notes app is upgraded to 4.9.3."
2024-06-17 14:03:54 +00:00
} ,
{
"lang" : "es" ,
"value" : "La aplicaci\u00f3n Nextcloud Notes es una aplicaci\u00f3n para tomar notas sin distracciones para Nextcloud. Si un atacante lograba compartir una carpeta llamada `Notas/` con un usuario reci\u00e9n creado antes de iniciar sesi\u00f3n, la aplicaci\u00f3n Notas usar\u00eda esa carpeta para almacenar las notas personales. Se recomienda actualizar la aplicaci\u00f3n Nextcloud Notes a 4.9.3."
2024-06-14 18:03:12 +00:00
}
] ,
"metrics" : {
"cvssMetricV31" : [
2024-08-19 16:03:14 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.6 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.1 ,
"impactScore" : 2.5
} ,
2024-06-14 18:03:12 +00:00
{
"source" : "security-advisories@github.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "LOW" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "LOW" ,
"integrityImpact" : "LOW" ,
"availabilityImpact" : "LOW" ,
"baseScore" : 4.6 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 1.2 ,
"impactScore" : 3.4
}
]
} ,
"weaknesses" : [
2024-08-19 16:03:14 +00:00
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-862"
}
]
} ,
2024-06-14 18:03:12 +00:00
{
"source" : "security-advisories@github.com" ,
"type" : "Secondary" ,
"description" : [
{
"lang" : "en" ,
"value" : "CWE-284"
}
]
}
] ,
2024-08-19 16:03:14 +00:00
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:nextcloud:notes:*:*:*:*:*:nextcloud:*:*" ,
"versionStartIncluding" : "4.6.0" ,
"versionEndExcluding" : "4.9.3" ,
"matchCriteriaId" : "E2A24E4C-43C7-4799-9C22-8CD82C579B49"
}
]
}
]
}
] ,
2024-06-14 18:03:12 +00:00
"references" : [
{
"url" : "https://github.com/nextcloud/notes/pull/1260" ,
2024-08-19 16:03:14 +00:00
"source" : "security-advisories@github.com" ,
"tags" : [
"Patch"
]
2024-06-14 18:03:12 +00:00
} ,
{
"url" : "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wfqv-cx85-7rjx" ,
2024-08-19 16:03:14 +00:00
"source" : "security-advisories@github.com" ,
"tags" : [
"Third Party Advisory"
]
2024-06-14 18:03:12 +00:00
} ,
{
"url" : "https://hackerone.com/reports/2254151" ,
2024-08-19 16:03:14 +00:00
"source" : "security-advisories@github.com" ,
"tags" : [
"Issue Tracking"
]
2024-06-14 18:03:12 +00:00
}
]
}