Improper Access Control Affecting nextcloud-desktop package, versions <3.15.0-1


Severity

Recommended
low

Based on default assessment until relevant scores are available.

Threat Intelligence

EPSS
0.01% (1st percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Access Control vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-DEBIANUNSTABLE-NEXTCLOUDDESKTOP-10180118
  • published17 May 2025
  • disclosed16 May 2025

Introduced: 16 May 2025

NewCVE-2025-47792  (opens in a new tab)
CWE-284  (opens in a new tab)

How to fix?

Upgrade Debian:unstable nextcloud-desktop to version 3.15.0-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream nextcloud-desktop package and not the nextcloud-desktop package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Nextcloud Desktop is the desktop sync client for Nextcloud. In versions of Nextcloud Desktop prior to 3.15, 3rdparty applications already installed on a user machine can create link shares for almost all data via the socket API. These shares can then be easily sent off to an external service. Nextcloud Desktop fixes the issue in version 3.15. No known workarounds are available.