CVE-2024-22401: All users can reset the allowed apps list for Nextcloud Guest App users
Nextcloud guests app is a utility to create guest users which can only see files shared with them. In affected versions users could change the allowed list of apps, allowing them to use apps that were not intended to be used. It is recommended that the Guests app is upgraded to 2.4.1, 2.5.1 or 3.0.1. There are no known workarounds for this vulnerability.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nextcloud Guests Appto a version that resolves this vulnerability.Fixed in 2.4.1 - Upgrade
Upgrade
Nextcloud Guests Appto a version that resolves this vulnerability.Fixed in 2.5.1 - Upgrade
Upgrade
Nextcloud Guests Appto a version that resolves this vulnerability.Fixed in 3.0.1
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22401?
CVE-2024-22401 has been classified as a moderate severity vulnerability affecting the Nextcloud guests app.
How do I fix CVE-2024-22401?
To fix CVE-2024-22401, upgrade the Nextcloud guests app to version 2.4.1 or later.
Which versions of the Nextcloud guests app are affected by CVE-2024-22401?
CVE-2024-22401 affects versions of the Nextcloud guests app prior to 2.4.1, as well as versions 2.5.0 and 3.0.0.
What can attackers do in the context of CVE-2024-22401?
Attackers exploiting CVE-2024-22401 can change the allowed list of apps for guest users, potentially enabling unauthorized access to restricted applications.
Is user data at risk due to CVE-2024-22401?
Yes, user data may be at risk due to CVE-2024-22401 if attackers can manipulate guest permissions to access sensitive files or applications.