VulnerabilityModified
CVE-2022-41970
Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images.
MEDIUM 5.3EPSS 0.63%
Does this matter?
Lower severity and a low EPSS score (0.63%). Track it; it rarely justifies an emergency change on its own.
Description
Nextcloud Server is an open source personal cloud server. Prior to versions 24.0.7 and 25.0.1, disabled download shares still allow download through preview images. Images could be downloaded and previews of documents (first page) can be downloaded without being watermarked. Versions 24.0.7 and 25.0.1 contain a fix for this issue. No known workarounds are available.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- EPSS
- 0.63% probability · 48th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284, CWE-863
- Affected
- nextcloud/nextcloud server
- Source
- security-advisories@github.com
References
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9mh6-cph8-772cThird Party Advisory
- https://github.com/nextcloud/server/pull/34788Patch, Third Party Advisory
- https://hackerone.com/reports/1745766Permissions Required, Third Party Advisory
- https://github.com/nextcloud/security-advisories/security/advisories/GHSA-9mh6-cph8-772cThird Party Advisory
- https://github.com/nextcloud/server/pull/34788Patch, Third Party Advisory
- https://hackerone.com/reports/1745766Permissions Required, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.