Nextcloud · Nextcloud Server · CVE-2022-24889
**Name of the Vulnerable Software and Affected Versions**
Nextcloud Server versions prior to 21.0.8
Nextcloud Server versions prior to 22.2.4
Nextcloud Server versions prior to 23.0.1
**Description**
The issue allows attackers to trick administrators into enabling unnecessary "recommended" apps for the Nextcloud server, expanding their attack surface.
**Recommendations**
For versions prior to 21.0.8, update to version 21.0.8 or later.
For versions prior to 22.2.4, update to version 22.2.4 or later.
For versions prior to 23.0.1, update to version 23.0.1 or later.