First published: Thu Jan 18 2024(Updated: )
Nextcloud files Zip app is a tool to create zip archives from one or multiple files from within Nextcloud. In affected versions users can download "view-only" files by zipping the complete folder. It is recommended that the Files ZIP app is upgraded to 1.2.1, 1.4.1, or 1.5.0. Users unable to upgrade should disable the file zip app.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Nextcloud Zipper | <1.2.1 | |
Nextcloud Zipper | =1.4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-22404 is considered high due to the potential for unauthorized access to 'view-only' files.
To fix CVE-2024-22404, upgrade the Nextcloud Files ZIP app to versions 1.2.1, 1.4.1, or 1.5.0.
Affected versions of Nextcloud's Files ZIP app include versions before 1.2.1 and version 1.4.0.
CVE-2024-22404 is a vulnerability that allows users to download files that should only be viewable.
Yes, a patch is available by upgrading to the recommended versions of the Files ZIP app.