Bug 2259147 (CVE-2024-22400)
| Summary: | CVE-2024-22400 nextcloud: users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Rohit Keshri <rkeshri> |
| Component: | vulnerability | Assignee: | Product Security <prodsec-ir-bot> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for this issue.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2259148, 2259149, 2259150, 2259151, 2259152, 2259153, 2259154 | ||
| Bug Blocks: | |||
|
Description
Rohit Keshri
2024-01-19 08:28:12 UTC
Created nextcloud tracking bugs for this issue: Affects: fedora-all [bug 2259149] Created nextcloud:23/nextcloud tracking bugs for this issue: Affects: epel-all [bug 2259150] Affects: fedora-all [bug 2259152] Created nextcloud:24/nextcloud tracking bugs for this issue: Affects: epel-all [bug 2259148] Affects: fedora-all [bug 2259153] Created nextcloud:nextcloud-22/nextcloud tracking bugs for this issue: Affects: epel-all [bug 2259151] Created nextcloud:nextcloud-stable/nextcloud tracking bugs for this issue: Affects: fedora-all [bug 2259154] |