CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
LOW
CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L
AI Score
Confidence
Low
EPSS
Percentile
5.0%
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud
Server with your computer. A code injection in Nextcloud Desktop Client for
macOS allowed to load arbitrary code when starting the client with
DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the
Nextcloud Desktop client is upgraded to 3.12.0.
Author | Note |
---|---|
rodrigo-zaiden | Only affects macOS |
github.com/nextcloud/desktop/pull/6378
github.com/nextcloud/security-advisories/security/advisories/GHSA-4mf7-v63m-99p7
hackerone.com/reports/2307625
launchpad.net/bugs/cve/CVE-2024-37885
nvd.nist.gov/vuln/detail/CVE-2024-37885
security-tracker.debian.org/tracker/CVE-2024-37885
www.cve.org/CVERecord?id=CVE-2024-37885