Cyber Resilience

CVE-2024-46958

Nextcloud Desktop 3.13.1 – 3.13.4

Published
16 September 2024
Modified
13 March 2025
Patch / advisory
CVSS Score v3.1 9.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score 0.0056 43th percentile
Risk Priority 67 floored blend · peak EPSS

Summary

CVE-2024-46958 is a critical-severity an unspecified weakness vulnerability in Nextcloud Desktop. Its CVSS base score is 9.1 (Critical).

Operationally, ranked at the 43th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

In Nextcloud Desktop Client 3.13.1 through 3.13.3 on Linux, synchronized files (between the server and client) may become world writable or world readable. This is fixed in 3.13.4.

CWE(s)

Related Threats

CVEs Like This One

CVE-2024-49994Same product: Linux Linux Kernel
CVE-2024-39509Same product: Linux Linux Kernel
CVE-2024-40969Same product: Linux Linux Kernel
CVE-2024-50238Same product: Linux Linux Kernel
CVE-2024-43863Same product: Linux Linux Kernel
CVE-2024-53147Same product: Linux Linux Kernel
CVE-2024-50056Same product: Linux Linux Kernel
CVE-2024-35841Same product: Linux Linux Kernel
CVE-2024-44958Same product: Linux Linux Kernel
CVE-2024-47726Same product: Linux Linux Kernel

Affected Assets

nextcloud
desktop
3.13.1 — 3.13.4

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References