Lucene search

K
nextcloudNextcloudGHSA-4MF7-V63M-99P7
HistoryJun 14, 2024 - 2:34 p.m.

Code injection in Nextcloud Desktop Client for macOS

2024-06-1414:34:49
github.com
8
nextcloud
desktop client
macos
code injection
arbitrary code
upgrade
security advisory
hackerone
pullrequest

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

5.0%

Description

Impact

A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment.

Patches

It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0

Workarounds

  • No workaround available

References

For more information

If you have any questions or comments about this advisory:

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

5.0%