CVE-2024-22404
Last modified
CVE-2024-22404 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Zipper | < 1.2.1 |
| Nextcloud | Zipper | 1.4.0 |
References
- https://hackerone.com/reports/2247457Permissions Required, Third Party Advisory
- https://hackerone.com/reports/2247457Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-22404?
How severe is CVE-2024-22404?
How do I fix CVE-2024-22404?
Are you affected by CVE-2024-22404?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
