Nextcloud global site selector authentication bypass
CVE-2024-22212
What is CVE-2024-22212?
The Nextcloud Global Site Selector presents a serious vulnerability involving an authentication bypass due to a flaw in the password verification method. This vulnerability allows an unauthorized attacker to authenticate as any other user, potentially leading to unauthorized access to sensitive information and user accounts. To mitigate this security risk, it is essential to upgrade to the following secure versions: 1.4.1, 2.1.2, 2.3.4, or 2.4.5. Currently, there are no known workarounds for this issue, highlighting the urgency of applying the necessary updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
security-advisories >= 1.1.0, < 1.4.1 < 1.1.0, 1.4.1
security-advisories >= 2.0.0, < 2.1.2 < 2.0.0, 2.1.2
security-advisories >= 2.2.0, < 2.3.4 < 2.2.0, 2.3.4
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved