CVE-2022-24889
Summary
| CVE | CVE-2022-24889 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-04-27 15:15:00 UTC |
| Updated | 2022-10-25 20:51:00 UTC |
| Description | Nextcloud Server is the file server software for Nextcloud, a self-hosted productivity platform. Prior to versions 21.0.8, 22.2.4, and 23.0.1, it is possible to trick administrators into enabling "recommended" apps for the Nextcloud server that they do not need, thus expanding their attack surface unnecessarily. This issue is fixed in versions 21.0.8 , 22.2.4, and 23.0.1. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Nextcloud: Multiple Vulnerabilities (GLSA 202208-17) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Improve install process by Pytal · Pull Request #30615 · nextcloud/server · GitHub |
MISC |
github.com |
|
| HackerOne |
MISC |
hackerone.com |
|
| Force an admin to install recommended applications · Advisory · nextcloud/security-advisories · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 710590 Gentoo Linux Nextcloud Multiple Vulnerabilities (GLSA 202208-17)