Medium severity6.5NVD Advisory· Published Jun 2, 2022· Updated Jun 17, 2026
CVE-2022-31024
CVE-2022-31024
Description
richdocuments is the repository for NextCloud Collabra, the app for Nextcloud Office collaboration. Prior to versions 6.0.0, 5.0.4, and 4.2.6, a user could be tricked into working against a remote Office by sending them a federated share. richdocuments versions 6.0.0, 5.0.4 and 4.2.6 contain a fix for this issue. There are currently no known workarounds available.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:nextcloud:richdocuments:*:*:*:*:*:*:*:*range: <4.2.6
- cpe:2.3:a:nextcloud:richdocuments:6.0.0:beta1:*:*:*:*:*:*
- (no CPE)range: <6.0.0, <5.0.4, <4.2.6
- nextcloud/security-advisoriesv5Range: < 4.2.6
Patches
Vulnerability mechanics
References
3- github.com/nextcloud/richdocuments/pull/2161nvdIssue TrackingPatchThird Party Advisory
- github.com/nextcloud/security-advisories/security/advisories/GHSA-94hr-7g4v-f53rnvdIssue TrackingThird Party Advisory
- hackerone.com/reports/1210424nvdPermissions Required
News mentions
0No linked articles in our index yet.