PT-2022-16959 · Nextcloud+1 · Nextcloud Server+1

Igorpyan

·

Published

2022-04-27

·

Updated

2022-10-25

·

CVE-2022-24889

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server versions prior to 21.0.8 Nextcloud Server versions prior to 22.2.4 Nextcloud Server versions prior to 23.0.1
Description The issue allows attackers to trick administrators into enabling unnecessary "recommended" apps for the Nextcloud server, expanding their attack surface.
Recommendations For versions prior to 21.0.8, update to version 21.0.8 or later. For versions prior to 22.2.4, update to version 22.2.4 or later. For versions prior to 23.0.1, update to version 23.0.1 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2504
ALT-PU-2022-2555
CVE-2022-24889
GHSA-5VW6-6PRG-GVW6

Affected Products

Alt Linux
Nextcloud Server