CVE-2024-37885

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
14/06/2024
Last modified:
19/08/2024

Description

The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the enviroment. It is recommended that the Nextcloud Desktop client is upgraded to 3.12.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nextcloud:desktop:*:*:*:*:*:*:*:* 3.12.0 (excluding)
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*