高度な大規模言語モデル技術を使用していますが、出力には不正確または古い情報が含まれる可能性があります。Shenlongはデータの正確性を確保するよう努めていますが、実際の状況に基づいて検証・判断してください。
| ベンダー | プロダクト | 影響を受けるバージョン | CPE | 購読 |
|---|---|---|---|---|
| nextcloud | security-advisories | >=2.2.0, < 2.2.10 | - |
| # | POC説明 | ソースリンク | Shenlongリンク |
|---|
公開POCは見つかりませんでした。
ログインしてAI POCを生成| CVE-2024-52508 | 8.2 HIGH | Nextcloud Mail auto configurator can be tricked into sending account information to wrong |
| CVE-2024-52511 | 6.3 MEDIUM | Nextcloud Tables has an Authorization Bypass Through User-Controlled Key in Tables |
| CVE-2024-52515 | 5.7 MEDIUM | Nextcloud Server has incomplete sanitization of SVG files allows to embed other images int |
| CVE-2024-52520 | 5.7 MEDIUM | Nextcloud Server's link reference provider can be tricked into downloading bigger files th |
| CVE-2024-52517 | 4.6 MEDIUM | Nextcloud Server's global credentials of external storages are sent back to the frontend |
| CVE-2024-52523 | 4.6 MEDIUM | Nextcloud Server Custom defined credentials of external storages are sent back to the fron |
| CVE-2024-52518 | 4.4 MEDIUM | Nextcloud Server is missing password confirmation when changing external storage options |
| CVE-2024-52510 | 4.2 MEDIUM | Nextcloud Desktop client behaves incorrectly if the initial end-to-end-encryption signatur |
| CVE-2024-52514 | 4.1 MEDIUM | Nextcloud Server allows users to copy folder that contain files that are blocked by the fi |
| CVE-2024-52507 | 3.5 LOW | Share information of the Nextcloud Tables app is not limited to affected users |
| CVE-2024-52512 | 3.3 LOW | Nextcloud User OIDC has an open redirection when logging in with User OIDC |
| CVE-2024-52516 | 3.0 LOW | Nextcloud Server's shares are not removed when user is limited to share with in their grou |
| CVE-2024-52519 | 2.7 LOW | Nextcloud Server's OAuth2 client secrets were stored in a recoverable way |
| CVE-2024-52513 | 2.6 LOW | Nextcloud Server's Attachments folder for Text app is accessible on "Files drop" and "Pass |
| CVE-2024-52521 | 2.6 LOW | Nextcloud Server has a potential hash collision for background jobs could skip queuing the |
| CVE-2024-52525 | 1.8 LOW | Nextcloud Server User password is available in memory of the PHP process |
まだコメントはありません