Nextcloud Global Site Selector is a tool which allows you to run multiple small Nextcloud instances and redirect users to the right server. A problem in the password verification method allows an attacker to authenticate as another user. It is recommended that the Nextcloud Global Site Selector is upgraded to version 1.4.1, 2.1.2, 2.3.4 or 2.4.5. There are no known workarounds for this issue.
References
Link | Resource |
---|---|
https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 | Patch Vendor Advisory |
https://hackerone.com/reports/2248689 | Issue Tracking Third Party Advisory |
https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee | Patch |
https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 | Patch Vendor Advisory |
https://hackerone.com/reports/2248689 | Issue Tracking Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 08:55
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.6 |
References | () https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee - Patch | |
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 - Patch, Vendor Advisory | |
References | () https://hackerone.com/reports/2248689 - Issue Tracking, Third Party Advisory |
26 Jan 2024, 14:58
Type | Values Removed | Values Added |
---|---|---|
References | () https://hackerone.com/reports/2248689 - Issue Tracking, Third Party Advisory | |
References | () https://github.com/nextcloud/security-advisories/security/advisories/GHSA-vj5q-f63m-wp77 - Patch, Vendor Advisory | |
References | () https://github.com/nextcloud/globalsiteselector/commit/ab5da57190d5bbc79079ce4109b6bcccccd893ee - Patch | |
First Time |
Nextcloud global Site Selector
Nextcloud |
|
CPE | cpe:2.3:a:nextcloud:global_site_selector:*:*:*:*:*:*:*:* | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
18 Jan 2024, 19:25
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-18 19:15
Updated : 2024-11-21 08:55
NVD link : CVE-2024-22212
Mitre link : CVE-2024-22212
CVE.ORG link : CVE-2024-22212
JSON object : View
Products Affected
nextcloud
- global_site_selector
CWE
CWE-306
Missing Authentication for Critical Function