CVE-2024-22402
Last modified
CVE-2024-22402 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. EPSS estimates a 0.51% chance of exploitation in the next 30 days.
Description
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a permissions bypass. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Guests | < 2.4.1 |
| Nextcloud | Guests | 2.5.0 |
| Nextcloud | Guests | 3.0.0 |
References
- https://github.com/nextcloud/guests/pull/1082Patch, Vendor Advisory
- https://hackerone.com/reports/2251074Permissions Required, Third Party Advisory
- https://github.com/nextcloud/guests/pull/1082Patch, Vendor Advisory
- https://hackerone.com/reports/2251074Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-22402?
How severe is CVE-2024-22402?
How do I fix CVE-2024-22402?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-22397Improper Neutralization of Input During Web Page Generation …8.3
- CVE-2024-22398An improper Limitation of a Pathname to a Restricted Directo…4.9
- CVE-2024-22399Deserialization of Untrusted Data vulnerability in Apache Se…9.8
- CVE-2024-2240Docker daemon in Brocade SANnav before SANnav 2.3.1b runs wi…7.2
- CVE-2024-22400Nextcloud User Saml is an app for authenticating Nextcloud u…6.1
- CVE-2024-22401Nextcloud guests app is a utility to create guest users whic…4.3
- CVE-2024-22403Nextcloud server is a self hosted personal cloud system. In …3.7
- CVE-2024-22404Nextcloud files Zip app is a tool to create zip archives fro…4.3
- CVE-2024-22405XADMaster is an objective-C library for archive and file una…5.5
- CVE-2024-22406Shopware is an open headless commerce platform. The Shopware…9.8
- CVE-2024-22407Shopware is an open headless commerce platform. In the Shopw…6.5
- CVE-2024-22408Shopware is an open headless commerce platform. The implemen…8.1
Are you affected by CVE-2024-22402?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
