Low severity3.1NVD Advisory· Published Jan 18, 2024· Updated Jun 17, 2026
CVE-2024-22400
CVE-2024-22400
Description
Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for this issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:nextcloud:sso_\&_saml_authentication:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:nextcloud:sso_\&_saml_authentication:*:*:*:*:*:*:*:*range: >=5.0.0,<5.1.5
- cpe:2.3:a:nextcloud:sso_\&_saml_authentication:6.0.0:*:*:*:*:*:*:*
- Range: >= 5.0.0, < 5.1.5
Patches
Vulnerability mechanics
References
4- github.com/nextcloud/user_saml/commit/b184304a476deeba36e92b70562d5de7c2f85f8anvdPatch
- github.com/nextcloud/user_saml/pull/788nvdPatch
- github.com/nextcloud/security-advisories/security/advisories/GHSA-622q-xhfr-xmv7nvdVendor Advisory
- hackerone.com/reports/2263044nvdPermissions RequiredThird Party Advisory
News mentions
0No linked articles in our index yet.