CVE-2024-22404
Last modified
CVE-2024-22404 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nextcloud | Zipper | < 1.2.1 |
| Nextcloud | Zipper | 1.4.0 |
References
- https://hackerone.com/reports/2247457Permissions Required, Third Party Advisory
- https://hackerone.com/reports/2247457Permissions Required, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-22404?
How severe is CVE-2024-22404?
How do I fix CVE-2024-22404?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-22399Deserialization of Untrusted Data vulnerability in Apache Se…9.8
- CVE-2024-2240Docker daemon in Brocade SANnav before SANnav 2.3.1b runs wi…7.2
- CVE-2024-22400Nextcloud User Saml is an app for authenticating Nextcloud u…6.1
- CVE-2024-22401Nextcloud guests app is a utility to create guest users whic…4.3
- CVE-2024-22402Nextcloud guests app is a utility to create guest users whic…5.4
- CVE-2024-22403Nextcloud server is a self hosted personal cloud system. In …3.7
- CVE-2024-22405XADMaster is an objective-C library for archive and file una…5.5
- CVE-2024-22406Shopware is an open headless commerce platform. The Shopware…9.8
- CVE-2024-22407Shopware is an open headless commerce platform. In the Shopw…6.5
- CVE-2024-22408Shopware is an open headless commerce platform. The implemen…8.1
- CVE-2024-22409DataHub is an open-source metadata platform. In affected ver…8.8
- CVE-2024-2241Improper access control in the user interface in Devolutions…6.3
Are you affected by CVE-2024-22404?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
