CVE-2022-24888
Last modified
CVE-2022-24888 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1, it is possible to create files and folders that have leading and trailing \n, \r, \t, and \v characters. EPSS estimates a 1.23% chance of exploitation in the next 30 days.
Description
Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1, it is possible to create files and folders that have leading and trailing \n, \r, \t, and \v characters. The server rejects files and folders that have these characters in the middle of their names, so this might be an opportunity for injection. This issue is fixed in versions 20.0.14.4, 21.0.8, 22.2.4, and 23.0.1. There are currently no known workarounds.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Nextcloud Server | < 20.0.14.4 |
| Nextcloud | Nextcloud Server | >= 21.0.0, < 21.0.8 |
| Nextcloud | Nextcloud Server | >= 22.0.0, < 22.2.4 |
| Nextcloud | Nextcloud Server | >= 23.0.0, < 23.0.1 |
References
- https://github.com/nextcloud/server/pull/29895Patch, Third Party Advisory
- https://hackerone.com/reports/1402249Permissions Required, Third Party Advisory
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
- https://github.com/nextcloud/server/pull/29895Patch, Third Party Advisory
- https://hackerone.com/reports/1402249Permissions Required, Third Party Advisory
- https://security.gentoo.org/glsa/202208-17Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-24888?
How severe is CVE-2022-24888?
How do I fix CVE-2022-24888?
Are you affected by CVE-2022-24888?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
