PT-2024-19279 · Nextcloud · Nextcloud Global Site Selector

Ry0Tak

·

Published

2024-01-18

·

Updated

2024-01-26

·

CVE-2024-22212

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nextcloud Global Site Selector versions prior to 1.4.1 Nextcloud Global Site Selector versions prior to 2.1.2 Nextcloud Global Site Selector versions prior to 2.3.4 Nextcloud Global Site Selector versions prior to 2.4.5
Description The Nextcloud Global Site Selector is a tool that allows running multiple small Nextcloud instances and redirecting users to the right server. A problem in the password verification method allows an attacker to authenticate as another user.
Recommendations For versions prior to 1.4.1, upgrade to version 1.4.1. For versions prior to 2.1.2, upgrade to version 2.1.2. For versions prior to 2.3.4, upgrade to version 2.3.4. For versions prior to 2.4.5, upgrade to version 2.4.5. As a temporary workaround, consider disabling the password verification function until a patch is available.

Exploit

Fix

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2024-22212
GHSA-VJ5Q-F63M-WP77

Affected Products

Nextcloud Global Site Selector