Bug 2259088 (CVE-2024-22212) - CVE-2024-22212 nextcloud: password verification method allows an attacker to authenticate as another user
Summary: CVE-2024-22212 nextcloud: password verification method allows an attacker to ...
Keywords:
Status: NEW
Alias: CVE-2024-22212
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2259089 2259090 2259091 2259092 2259093 2259094 2259095
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-01-19 05:34 UTC by Rohit Keshri
Modified: 2024-01-19 05:41 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2024-01-19 05:34:51 UTC
Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud Global Site Selector is upgraded to version 1.4.1, 2.1.2, 2.3.4 or 2.4.5. There are no known workarounds for this issue.

https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77
https://hackerone.com/reports/2248689

Comment 1 Rohit Keshri 2024-01-19 05:41:34 UTC
Created nextcloud tracking bugs for this issue:

Affects: fedora-all [bug 2259089]


Created nextcloud:23/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2259090]
Affects: fedora-all [bug 2259093]


Created nextcloud:24/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2259091]
Affects: fedora-all [bug 2259094]


Created nextcloud:nextcloud-22/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2259092]


Created nextcloud:nextcloud-stable/nextcloud tracking bugs for this issue:

Affects: fedora-all [bug 2259095]


Note You need to log in before you can comment on or make changes to this bug.