Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud Global Site Selector is upgraded to version 1.4.1, 2.1.2, 2.3.4 or 2.4.5. There are no known workarounds for this issue.
References
Link | Resource |
---|---|
https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 | Patch Vendor Advisory |
https://hackerone.com/reports/2248689 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-01-18 19:15
Updated : 2024-01-26 14:58
NVD link : CVE-2024-22212
Mitre link : CVE-2024-22212
CVE.ORG link : CVE-2024-22212
JSON object : View
Products Affected
nextcloud
- global_site_selector
CWE
CWE-306
Missing Authentication for Critical Function