CVE-2024-30247: Command Injection as root in NextCloudPi web panel
NextcloudPi is a ready to use image for Virtual Machines, Raspberry Pi, Odroid HC1, Rock64 and other boards. A command injection vulnerability in NextCloudPi allows command execution as the root user via the NextCloudPi web-panel. Due to a security misconfiguration this can be used by anyone with access to NextCloudPi web-panel, no authentication is required. It is recommended that the NextCloudPi is upgraded to 1.53.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-30247?
CVE-2024-30247 is classified as a high-severity command injection vulnerability.
How do I fix CVE-2024-30247?
To fix CVE-2024-30247, upgrade NextCloudPi to version 1.53.2 or later.
What versions of NextCloudPi are affected by CVE-2024-30247?
CVE-2024-30247 affects all versions of NextCloudPi up to and including 1.53.1.
What impact does CVE-2024-30247 have on my system?
CVE-2024-30247 allows attackers to execute arbitrary commands as the root user via the web panel.
Is there a workaround for CVE-2024-30247?
Currently, a workaround for CVE-2024-30247 is not recommended; updating to the patched version is advised.