CVE-2024-22400: Open redirect in user_saml via RelayState parameter in Nextcloud User Saml
Nextcloud User Saml is an app for authenticating Nextcloud users using SAML. In affected versions users can be given a link to the Nextcloud server and end up on a uncontrolled thirdparty server. It is recommended that the User Saml app is upgraded to version 5.1.5, 5.2.5, or 6.0.1. There are no known workarounds for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud User Samlto a version that resolves this vulnerability.Fixed in 5.1.5 - Upgrade
Upgrade
Nextcloud User Samlto a version that resolves this vulnerability.Fixed in 5.2.5 - Upgrade
Upgrade
Nextcloud User Samlto a version that resolves this vulnerability.Fixed in 6.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22400?
CVE-2024-22400 has a moderate severity rating due to potential unauthorized access via untrusted third-party servers.
How do I fix CVE-2024-22400?
To fix CVE-2024-22400, upgrade the Nextcloud User SAML app to version 5.1.5, 5.2.5, or 6.0.1.
What versions of Nextcloud SAML are affected by CVE-2024-22400?
CVE-2024-22400 affects versions of the Nextcloud User SAML app from 5.0.0 up to 6.0.0.
What vulnerabilities does CVE-2024-22400 introduce for Nextcloud users?
CVE-2024-22400 can redirect users to an uncontrolled third-party server, posing security risks.
Is there a workaround for CVE-2024-22400 until I can update?
There is no documented workaround for CVE-2024-22400, so it is best to update to a safe version as soon as possible.