Nextcloud Server Group Permission Issue
CVE-2024-52516
4.3MEDIUM
What is CVE-2024-52516?
Nextcloud Server contains a permissions vulnerability affecting the way shared items are handled when a user is removed from a group. Specifically, if the server is configured to restrict sharing to users within specific groups, previously shared items remain accessible to the removed user. This issue highlights potential data exposure risks and emphasizes the necessity for users to upgrade to the latest versions to mitigate such vulnerabilities. The recommended updates are Nextcloud Server versions 22.2.11, 23.0.11, and 24.0.6, as well as Nextcloud Enterprise Server versions 22.2.11, 23.0.11, and 24.0.6.