Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-22401

Опубликовано: 18 янв. 2024
Источник: nvd
CVSS3: 4.1
CVSS3: 4.3
EPSS Низкий

Описание

Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nextcloud:guests:*:*:*:*:*:*:*:*
Версия до 2.4.1 (исключая)
cpe:2.3:a:nextcloud:guests:2.5.0:*:*:*:*:*:*:*
cpe:2.3:a:nextcloud:guests:3.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 55%
0.0032
Низкий

4.1 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-281

EPSS

Процентиль: 55%
0.0032
Низкий

4.1 Medium

CVSS3

4.3 Medium

CVSS3

Дефекты

CWE-281