Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-37885


The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.


Published

2024-06-14T16:15:13.570

Last Modified

2024-11-21T09:24:28.147

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.8 (LOW)

Weaknesses
  • Type: Secondary
    CWE-94
  • Type: Primary
    CWE-94

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nextcloud desktop < 3.12.0 Yes
Operating System apple macos - No

References