{"id":"CVE-2024-52511","summary":"Nextcloud Tables has an Authorization Bypass Through User-Controlled Key in Tables","details":"Nextcloud Tables allows users to to create tables with individual columns. By directly specifying the ID of a table or view, a malicious user could blindly insert new rows into tables they have no access to. It is recommended that the Nextcloud Tables is upgraded to 0.8.0.","aliases":["GHSA-4qqp-9h2g-7qg7"],"modified":"2026-08-12T03:51:44.962695392Z","published":"2024-11-15T17:22:41.184Z","database_specific":{"cwe_ids":["CWE-639"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52511.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://hackerone.com/reports/2671404"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/52xxx/CVE-2024-52511.json"},{"type":"ADVISORY","url":"https://github.com/nextcloud/security-advisories/security/advisories/GHSA-4qqp-9h2g-7qg7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-52511"},{"type":"FIX","url":"https://github.com/nextcloud/tables/commit/52846ad81fe192ee977f14c82a229b0d9cdc406c"},{"type":"FIX","url":"https://github.com/nextcloud/tables/pull/1351"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nextcloud/tables","events":[{"introduced":"cd9beb3f193f620546a1b4172e62a15a614f30ee"},{"fixed":"412c2b3177305e5b84701067690ce1af31e7d58d"},{"fixed":"52846ad81fe192ee977f14c82a229b0d9cdc406c"}],"database_specific":{"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:nextcloud:tables:*:*:*:*:*:nextcloud:*:*","extracted_events":[{"introduced":"0.6.0"},{"fixed":"0.8.0"}]}}],"versions":["v0.8.0-beta.3","v0.8.0-beta.2","v0.8.0-beta.1","v0.7.0","v0.7.0-beta.3","v0.7.0-beta.2","v0.7.0-beta.1","v0.6.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-52511.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:H/A:N"}]}