Permissions bypass in Nextcloud with the files zip app
CVE-2024-22404

4.1MEDIUM

Key Information:

Vendor

Nextcloud

Vendor
CVE Published:
18 January 2024

What is CVE-2024-22404?

Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.

Affected Version(s)

security-advisories >= 1.2.0, < 1.2.1 < 1.2.0, 1.2.1

security-advisories >= 1.3.0, < 1.4.1 < 1.3.0, 1.4.1

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2024-22404 : Permissions bypass in Nextcloud with the files zip app