PT-2022-26194 · Nextcloud+1 · Nextcloud Server+1

Juliushaertl

·

Published

2022-12-01

·

Updated

2023-02-03

·

CVE-2022-41970

CVSS v3.1

2.6

Low

VectorAV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Nextcloud Server versions prior to 24.0.7 Nextcloud Server versions prior to 25.0.1
Description The issue affects Nextcloud Server, an open source personal cloud server, where disabled download shares still allow download through preview images. This means images could be downloaded and previews of documents, specifically the first page, can be downloaded without being watermarked.
Recommendations For versions prior to 24.0.7, update to version 24.0.7 or later to resolve the issue. For versions prior to 25.0.1, update to version 25.0.1 or later to resolve the issue.

Exploit

Fix

Improper Access Control

Incorrect Authorization

Weakness Enumeration

Related Identifiers

ALT-PU-2023-1055
ALT-PU-2023-1176
CVE-2022-41970
GHSA-9MH6-CPH8-772C

Affected Products

Alt Linux
Nextcloud Server