Bug 2259129 (CVE-2024-22401) - CVE-2024-22401 nextcloud: users could change the allowed list of apps, allowing them to use apps that were not intended to be used
Summary: CVE-2024-22401 nextcloud: users could change the allowed list of apps, allowi...
Keywords:
Status: NEW
Alias: CVE-2024-22401
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2259132 2259133 2259134 2259135 2259136 2259137 2259138
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-01-19 08:13 UTC by Rohit Keshri
Modified: 2024-01-19 08:17 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2024-01-19 08:13:22 UTC
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.

https://github.com/nextcloud/guests/pull/1082
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-wr87-hx3w-29hh
https://hackerone.com/reports/2250398

Comment 1 Rohit Keshri 2024-01-19 08:17:35 UTC
Created nextcloud tracking bugs for this issue:

Affects: fedora-all [bug 2259132]


Created nextcloud:23/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2259133]
Affects: fedora-all [bug 2259136]


Created nextcloud:24/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2259134]
Affects: fedora-all [bug 2259137]


Created nextcloud:nextcloud-22/nextcloud tracking bugs for this issue:

Affects: epel-all [bug 2259135]


Created nextcloud:nextcloud-stable/nextcloud tracking bugs for this issue:

Affects: fedora-all [bug 2259138]


Note You need to log in before you can comment on or make changes to this bug.