Nextcloud是德国Nextcloud公司的一套开源的自托管文件同步和共享的通信应用平台。 Nextcloud Server 20.0.14.4、21.0.8、22.2.4 和 23.0.1之前版本存在安全漏洞,该漏洞源于应用允许可以创建具有前导和尾随 、 、 和 v 字符的文件和文件夹。攻击者利用该漏洞通过参数注入实现拒绝服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| nextcloud | security-advisories | < 20.0.14.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2022-24887 | 4.3 MEDIUM | Open Redirect in Nextcloud Talk |
| CVE-2022-24889 | 2.4 LOW | Insufficient Verification of Data Authenticity in Nextcloud Server |
| CVE-2022-24886 | 2.2 LOW | Exposure of Sensitive Information to an Unauthorized Actor in com.nextcloud.client |
| CVE-2022-24885 | 2.0 LOW | Improper Authentication in Nextcloud Android Files |
No comments yet