{
  "affected": [
    {
      "ranges": [
        {
          "database_specific": {
            "cpe": [
              "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:-:*:*:*",
              "cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:enterprise:*:*:*"
            ],
            "extracted_events": [
              {
                "introduced": "28.0.0"
              },
              {
                "fixed": "28.0.11"
              },
              {
                "introduced": "29.0.0"
              },
              {
                "fixed": "29.0.8"
              },
              {
                "introduced": "30.0.0"
              },
              {
                "fixed": "30.0.1"
              }
            ],
            "source": "CPE_RANGE"
          },
          "events": [
            {
              "introduced": "e15fcecaf0d382cebff924ec2b1f5319e130c0e8"
            },
            {
              "fixed": "c3f0921c1ec2bd99ed854e316e488b897ac251fa"
            },
            {
              "introduced": "36ae775aa7c9af22bf33645a2d8807206ec6c85f"
            },
            {
              "fixed": "c553bc228e1e625920faf49a2eb4e1046f9c83c2"
            },
            {
              "introduced": "656488893e2175e19fbe273d76a5e16a598000c7"
            },
            {
              "fixed": "fd746c69f4e5122aebe3e136837473a60fccd3b3"
            }
          ],
          "repo": "https://github.com/nextcloud/server",
          "type": "GIT"
        },
        {
          "database_specific": {
            "extracted_events": [
              {
                "introduced": "28.0.0"
              },
              {
                "fixed": "28.0.11"
              },
              {
                "introduced": "29.0.0"
              },
              {
                "fixed": "29.0.8"
              },
              {
                "introduced": "30.0.0"
              },
              {
                "fixed": "30.0.1"
              }
            ],
            "source": [
              "AFFECTED_FIELD",
              "REFERENCES"
            ]
          },
          "events": [
            {
              "introduced": "bc5f303a55928d884aff4bb9b7fc2a2f739bd03d"
            },
            {
              "introduced": "b1e7270d4d741272092fbf6e99b187889a7ff415"
            },
            {
              "introduced": "c04caee41ef53a27eb2e40d93b643563efe72da8"
            },
            {
              "fixed": "7d0ea2dad1f8aa8f853907ddd806b87b798d3046"
            },
            {
              "fixed": "cfd4502183fab9379eeac8174bb58e6ae73a8413"
            },
            {
              "fixed": "e28af3497d978c3164a15509c2ce146dc490a9c2"
            },
            {
              "fixed": "ca24b25c93b81626b4e457c260243edeab5f1548"
            }
          ],
          "repo": "https://github.com/nextcloud/text",
          "type": "GIT"
        }
      ]
    }
  ],
  "aliases": [
    "GHSA-gxph-5m4j-pfmj"
  ],
  "database_specific": {
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
      "CWE-200"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52513.json"
  },
  "details": "Nextcloud Server is a self hosted personal cloud system. After receiving a \"Files drop\" or \"Password protected\" share link a malicious user was able to download attachments that are referenced in Text files without providing the password. It is recommended that the Nextcloud Server is upgraded to 28.0.11, 29.0.8 or 30.0.1 and Nextcloud Enterprise Server is upgraded to 25.0.13.13, 26.0.13.9, 27.1.11.9, 28.0.11, 29.0.8 or 30.0.1.",
  "id": "CVE-2024-52513",
  "modified": "2026-07-15T01:49:01.521803393Z",
  "published": "2024-11-15T17:08:56.019Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/2376900"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52513.json"
    },
    {
      "type": "ADVISORY",
      "url": "https://github.com/nextcloud/security-advisories/security/advisories/GHSA-gxph-5m4j-pfmj"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-52513"
    },
    {
      "type": "FIX",
      "url": "https://github.com/nextcloud/text/commit/ca24b25c93b81626b4e457c260243edeab5f1548"
    },
    {
      "type": "FIX",
      "url": "https://github.com/nextcloud/text/pull/6485"
    }
  ],
  "schema_version": "1.8.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Nextcloud Server's Attachments folder for Text app is accessible on \"Files drop\" and \"Password protected\" shares"
}