Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud Global Site Selector is upgraded to version 1.4.1, 2.1.2, 2.3.4 or 2.4.5. There are no known workarounds for this issue.
References
Link | Resource |
---|---|
https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 | Patch Vendor Advisory |
https://hackerone.com/reports/2248689 | Issue Tracking Third Party Advisory |
https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 | Patch Vendor Advisory |
https://hackerone.com/reports/2248689 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee - Patch | |
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 - Patch, Vendor Advisory | |
References | () https://hackerone.com/reports/2248689 - Issue Tracking, Third Party Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.6 |
26 Jan 2024, 14:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee - Patch | |
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 - Patch, Vendor Advisory | |
References | () https://hackerone.com/reports/2248689 - Issue Tracking, Third Party Advisory | |
CPE | cpe:2.3:a:nextcloud:global_site_selector:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
18 Jan 2024, 19:25
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-18 19:15
Updated : 2024-11-21 08:55
NVD link : CVE-2024-22212
Mitre link : CVE-2024-22212
CVE.ORG link : CVE-2024-22212
JSON object : View
Products Affected
nextcloud
- global_site_selector
CWE
CWE-306
Missing Authentication for Critical Function