CVE-2022-24889

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
27/04/2022
Last modified:
25/10/2022

Description

Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server that they do not need, thus expanding their attack surface unnecessarily. This issue is fixed in versions 21.0.8 , 22.2.4, and 23.0.1.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 21.0.8 (excluding)
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 22.0.0 (including) 22.2.4 (excluding)
cpe:2.3:a:nextcloud:nextcloud_server:*:*:*:*:*:*:*:* 23.0.0 (including) 23.0.1 (excluding)