CVE-2024-22402

MEDIUM

Nextcloud Guests < 2.4.1 - Permissions Bypass via App Page Access

Title source: llm
STIX 2.1

Description

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users were able to load the first page of apps they were actually not allowed to access. Depending on the selection of apps installed this may present a permissions bypass. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_misc
https://github.com/nextcloud/guests/pull/1082
Permissions Required, Third Party Advisory x_refsource_misc
https://hackerone.com/reports/2251074

Scores

CVSS v3 5.4
EPSS 0.0051
EPSS Percentile 39.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-281
Status published
Products (3)
nextcloud/guests 2.5.0
nextcloud/guests 3.0.0
nextcloud/guests < 2.4.1
Published Jan 18, 2024
Tracked Since Feb 18, 2026