VYPR

security-advisories

by Nextcloud

Source repositories

CVEs (233)

  • CVE-2024-37316MedJun 14, 2024
    risk 0.00cvss 4.6epss 0.00

    Nextcloud Calendar is a calendar app for Nextcloud. Authenticated users could create an event with manipulated attachment data leading to a bad redirect for participants when clicked. It is recommended that the Nextcloud Calendar App is upgraded to 4.6.8 or 4.7.2.

  • CVE-2024-37315LowJun 14, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Server is a self hosted personal cloud system. An attacker with read-only access to a file is able to restore older versions of a document when the files_versions app is enabled. It is recommended that the Nextcloud Server is upgraded to 26.0.12, 27.1.7 or 28.0.3 and…

  • CVE-2024-37314LowJun 14, 2024
    risk 0.00cvss 3.5epss 0.00

    Nextcloud Photos is a photo management app. Users can remove photos from the album of registered users. It is recommended that the Nextcloud Server is upgraded to 25.0.7 or 26.0.2 and the Nextcloud Enterprise Server is upgraded to 25.0.7 or 26.0.2.

  • CVE-2024-37313HigJun 14, 2024
    risk 0.00cvss 7.3epss 0.00

    Nextcloud server is a self hosted personal cloud system. Under some circumstance it was possible to bypass the second factor of 2FA after successfully providing the user credentials. It is recommended that the Nextcloud Server is upgraded to 26.0.13, 27.1.8 or 28.0.4 and…

  • CVE-2024-37312MedJun 14, 2024
    risk 0.00cvss 6.3epss 0.01

    user_oidc app is an OpenID Connect user backend for Nextcloud. Missing access control on the ID4me endpoint allows an attacker to register an account eventually getting access to data that is available to all registered users. It is recommended that the OpenID Connect user…

  • CVE-2024-22404MedJan 18, 2024
    risk 0.00cvss 4.1epss 0.01

    Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0.…

  • CVE-2024-22402MedJan 18, 2024
    risk 0.00cvss 5.4epss 0.01

    Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a…

  • CVE-2024-22401MedJan 18, 2024
    risk 0.00cvss 4.1epss 0.00

    Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to…

  • CVE-2024-22403LowJan 18, 2024
    risk 0.00cvss 3.0epss 0.00

    Nextcloud server is a self hosted personal cloud system. In affected versions OAuth codes did not expire. When an attacker would get access to an authorization code they could authenticate at any time using the code. As of version 28.0.0 OAuth codes are invalidated after 10…

  • CVE-2024-22400LowJan 18, 2024
    risk 0.00cvss 3.1epss 0.00

    Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or…

  • CVE-2024-22213NonJan 18, 2024
    risk 0.00cvss 0.0epss 0.01

    Deck is a kanban style organization tool aimed at personal planning and project organization for teams integrated with Nextcloud. In affected versions users could be tricked into executing malicious code that would execute in their browser via HTML sent as a comment. It is…

  • CVE-2024-22212CriJan 18, 2024
    risk 0.00cvss 9.6epss 0.01

    Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud…

  • CVE-2023-49792MedDec 22, 2023
    risk 0.00cvss 5.3epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when a (reverse) proxy is…

  • CVE-2023-49791MedDec 22, 2023
    risk 0.00cvss 5.4epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. In Nextcloud Server prior to versions 26.0.9 and 27.1.4; as well as Nextcloud Enterprise Server prior to versions 23.0.12.13, 24.0.12.9, 25.0.13.4, 26.0.9, and 27.1.4; when an attacker manages…

  • CVE-2023-49790MedDec 22, 2023
    risk 0.00cvss 4.3epss 0.00

    The Nextcloud iOS Files app allows users of iOS to interact with Nextcloud, a self-hosted productivity platform. Prior to version 4.9.2, the application can be used without providing the 4 digit PIN code. Nextcloud iOS Files app should be upgraded to 4.9.2 to receive the patch.…

  • CVE-2023-48308LowDec 22, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud/Cloud is a calendar app for Nextcloud. An attacker can gain access to stacktrace and internal paths of the server when generating an exception while editing a calendar appointment. It is recommended that the Nextcloud Calendar app is upgraded to 4.5.3

  • CVE-2023-48307LowNov 21, 2023
    risk 0.00cvss 3.5epss 0.01

    Nextcloud Mail is the mail app for Nextcloud, a self-hosted productivity platform. Starting in version 1.13.0 and prior to version 2.2.8 and 3.3.0, an attacker can use an unprotected endpoint in the Mail app to perform a SSRF attack. Nextcloud Mail app versions 2.2.8 and 3.3.0…

  • CVE-2023-48306MedNov 21, 2023
    risk 0.00cvss 5.0epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11,…

  • CVE-2023-48305MedNov 21, 2023
    risk 0.00cvss 4.2epss 0.00

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and Nextcloud Enterprise Server, when the log level was set to debug, the user_ldap app logged…

  • CVE-2023-48304MedNov 21, 2023
    risk 0.00cvss 4.3epss 0.01

    Nextcloud Server provides data storage for Nextcloud, an open source cloud platform. Starting in version 25.0.0 and prior to versions 25.0.11, 26.0.6, and 27.1.0 of Nextcloud Server and starting in version 22.0.0 and prior to versions 22.2.10.16, 23.0.12.11, 24.0.12.7, 25.0.11,…

Page 4 of 12